Reynolds ransomware uses BYOVD to disable security before encryption
ID: 001638ce-12bc-5631-8339-7033cd2cb216
STIX ID: report--001638ce-12bc-5631-8339-7033cd2cb216
Feed Name: Security Affairs
Threat Score
Researchers disclosed Reynolds ransomware, which bundles a signed but vulnerable NsecKrnl driver and exploits CVE-2025-68947 (BYOVD) to kill EDR/antivirus processes and escalate privileges before encrypting files with the ".locked" extension; the campaign included a side-loaded loader and GotoHTTP access, and the report includes IoCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
