Black Basta Ransomware Integrates BYOVD Technique to Evade Defenses
ID: 786b9003-bde0-54f0-99ac-88f686c12228
STIX ID: report--786b9003-bde0-54f0-99ac-88f686c12228
Feed Name: GBHackers
Threat Score
A recent Black Basta/’Cardinal’ campaign embeds a vulnerable, signed driver (NsecSoft NSecKrnl, CVE-2025-68947) directly inside the ransomware binary to gain kernel-level control, disable major AV/EDR products (including Sophos, Symantec, CrowdStrike, Microsoft Defender), and rapidly encrypt files with a .locked extension — a tactic that increases stealth and reduces defender reaction time and signals a renewed, evolving activity from the group.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
