Qilin and Warlock Ransomware Use Vulnerable Drivers to Disable 300+ EDR Tools
ID: f34b396a-6ad5-582b-94ac-a8685869280f
STIX ID: report--f34b396a-6ad5-582b-94ac-a8685869280f
Feed Name: The Hacker News
Threat intelligence from Cisco Talos and Trend Micro details active ransomware operations by Qilin and Warlock that deploy a malicious DLL (msimg32.dll) and vulnerable signed drivers (e.g., renamed ThrottleStop.sys, NSecKrnl.sys) to perform BYOVD attacks that disable EDR solutions and persist in victim environments; the report outlines multi-stage in-memory loaders, kernel driver misuse to terminate 300+ EDR drivers, associated tooling (PsExec, Velociraptor, Rclone, etc.), and recommends strict driver signing policies, driver installation monitoring, and patching to mitigate these attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
