DeadLock Ransomware Uses BYOVD to Evade Security Measures
ID: 2920d7cb-60c5-500c-95c8-e2fff72b7747
STIX ID: report--2920d7cb-60c5-500c-95c8-e2fff72b7747
Feed Name: Infosecurity Magazine (News)
A Cisco Talos analysis describes a financially motivated campaign deploying DeadLock ransomware that leveraged a vulnerable Baidu Antivirus driver (CVE-2024-51324) via a BYOVD loader to kill security processes, escalate privileges, remove recovery options, and enable lateral movement; the C++ payload used process hollowing, a custom stream cipher to append ".dlock" to encrypted files, and communicated with victims via Session Messenger while demanding payment in Bitcoin or Monero.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
