logo

Reynolds Ransomware: BYOVD Evasion & NSecKrnl Abuse

ID: 54756e09-1fb0-5d83-9053-3a24f0eea55a

STIX ID: report--54756e09-1fb0-5d83-9053-3a24f0eea55a

Feed Name: Brandefense Blog

Threat Score
70/100

Date Published: 2026-02-25

Date Updated: 2026-04-27

Author: BRANDEFENSE

...
...

Reynolds is a February 2026 ransomware group observed using BYOVD (abusing a vulnerable NSecKrnl driver, tracked to CVE-2025-68947) to terminate security products prior to encrypting files (noted use of a ".locked" extension). The report provides one confirmed victim (business services), detailed IOCs (sample hashes, driver/service ImagePath pointing to C:\ProgramData\402.sys, ransom note path), YARA detection rules, observed tooling (GotoHTTP, qTox/onion communication), and IR recommendations focused on containment, driver block controls, hunting for suspicious driver installs, and validating backups.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.