logo

Black Basta Ransomware Integrates BYOVD Technique to Evade Defenses

ID: 786b9003-bde0-54f0-99ac-88f686c12228

STIX ID: report--786b9003-bde0-54f0-99ac-88f686c12228

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-02-09

Date Updated: 2026-07-21

Author: Mayura Kathir

...
...

A recent Black Basta/’Cardinal’ campaign embeds a vulnerable, signed driver (NsecSoft NSecKrnl, CVE-2025-68947) directly inside the ransomware binary to gain kernel-level control, disable major AV/EDR products (including Sophos, Symantec, CrowdStrike, Microsoft Defender), and rapidly encrypt files with a .locked extension — a tactic that increases stealth and reduces defender reaction time and signals a renewed, evolving activity from the group.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.