Black Basta Bundles BYOVD With Ransomware Payload
ID: a7afcab6-a617-585d-8be2-dcd8414fabbc
STIX ID: report--a7afcab6-a617-585d-8be2-dcd8414fabbc
Feed Name: Dark Reading
Symantec and Carbon Black researchers observed Black Basta bundle a vulnerable Windows driver (NSecSoft NSecKrnl, associated with CVE-2025-68947) directly into a ransomware payload as a BYOVD EDR-killer; the attack encrypted some files but reportedly failed to fully disable Symantec's product. The report highlights the benefits to attackers of embedding vulnerable drivers (quieter deployments, reduced gaps between evasion and payload), notes the growing popularity of BYOVD techniques among ransomware actors, and discusses defensive limitations such as reactive blocklists and the need for stronger platform-level mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
