logo

Black Basta Bundles BYOVD With Ransomware Payload

ID: a7afcab6-a617-585d-8be2-dcd8414fabbc

STIX ID: report--a7afcab6-a617-585d-8be2-dcd8414fabbc

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2026-02-09

Date Updated: 2026-04-21

Author: Rob Wright

...
...

Symantec and Carbon Black researchers observed Black Basta bundle a vulnerable Windows driver (NSecSoft NSecKrnl, associated with CVE-2025-68947) directly into a ransomware payload as a BYOVD EDR-killer; the attack encrypted some files but reportedly failed to fully disable Symantec's product. The report highlights the benefits to attackers of embedding vulnerable drivers (quieter deployments, reduced gaps between evasion and payload), notes the growing popularity of BYOVD techniques among ransomware actors, and discusses defensive limitations such as reactive blocklists and the need for stronger platform-level mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.