logo

DeadLock Ransomware Uses BYOVD to Evade Security Measures

ID: 2920d7cb-60c5-500c-95c8-e2fff72b7747

STIX ID: report--2920d7cb-60c5-500c-95c8-e2fff72b7747

Feed Name: Infosecurity Magazine (News)

Threat Score
78/100

Date Published: 2025-12-09

Date Updated: 2026-04-22

...
...

A Cisco Talos analysis describes a financially motivated campaign deploying DeadLock ransomware that leveraged a vulnerable Baidu Antivirus driver (CVE-2024-51324) via a BYOVD loader to kill security processes, escalate privileges, remove recovery options, and enable lateral movement; the C++ payload used process hollowing, a custom stream cipher to append ".dlock" to encrypted files, and communicated with victims via Session Messenger while demanding payment in Bitcoin or Monero.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.