Reynolds Ransomware Embeds BYOVD Driver to Disable EDR Security Tools
ID: 99ab6f16-e894-523a-b5f4-d33b9aa3fa19
STIX ID: report--99ab6f16-e894-523a-b5f4-d33b9aa3fa19
Feed Name: The Hacker News
Threat Score
**Reynolds ransomware** has been observed bundling a vulnerable, signed driver (NsecSoft NSecKrnl, CVE-2025-68947) inside the ransomware payload to perform BYOVD-based defense evasion—killing processes of major EDR/AV products—while ancillary activity (a side‑loaded loader and the GotoHTTP RAT) suggests pre-deployment footholds and persistence; the report situates this campaign within a wider uptick in professionalized, high-impact ransomware operations across 2025.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
