logo

Kasseika Ransomware Using BYOVD Trick to Disarm Security Pre-Encryption

ID: 039bc223-9bbd-5049-b632-886a53377ddd

STIX ID: report--039bc223-9bbd-5049-b632-886a53377ddd

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-01-24

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

**Kasseika** ransomware uses a BYOVD approach—dropping a signed vulnerable driver (Martini.sys / viragt64.sys) and a helper executable (Martini.exe) to disable hundreds of security products, then deploys a ransomware payload (smartscreen_protected.exe) that encrypts files with ChaCha20 and RSA, clears Windows event logs, and demands a 50 BTC ransom with additional extortion; the report also notes ties to BlackMatter and briefly describes BianLian's extortion activity and tooling overlaps with other groups.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.