logo

Qilin and Warlock Ransomware Use Vulnerable Drivers to Disable 300+ EDR Tools

ID: f34b396a-6ad5-582b-94ac-a8685869280f

STIX ID: report--f34b396a-6ad5-582b-94ac-a8685869280f

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-04-06

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Threat intelligence from Cisco Talos and Trend Micro details active ransomware operations by Qilin and Warlock that deploy a malicious DLL (msimg32.dll) and vulnerable signed drivers (e.g., renamed ThrottleStop.sys, NSecKrnl.sys) to perform BYOVD attacks that disable EDR solutions and persist in victim environments; the report outlines multi-stage in-memory loaders, kernel driver misuse to terminate 300+ EDR drivers, associated tooling (PsExec, Velociraptor, Rclone, etc.), and recommends strict driver signing policies, driver installation monitoring, and patching to mitigate these attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.