Reynolds Ransomware: BYOVD Evasion & NSecKrnl Abuse
ID: 54756e09-1fb0-5d83-9053-3a24f0eea55a
STIX ID: report--54756e09-1fb0-5d83-9053-3a24f0eea55a
Feed Name: Brandefense Blog
Reynolds is a February 2026 ransomware group observed using BYOVD (abusing a vulnerable NSecKrnl driver, tracked to CVE-2025-68947) to terminate security products prior to encrypting files (noted use of a ".locked" extension). The report provides one confirmed victim (business services), detailed IOCs (sample hashes, driver/service ImagePath pointing to C:\ProgramData\402.sys, ransom note path), YARA detection rules, observed tooling (GotoHTTP, qTox/onion communication), and IR recommendations focused on containment, driver block controls, hunting for suspicious driver installs, and validating backups.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
