#BYOVD
7 stories taggedBYOVD.

Spark RAT campaign hits Cambodia, using fake government and health notices as bait
Attackers are dropping Spark RAT on Cambodian targets through documents dressed as official government notices, health bulletins and property listings, while using a legitimate security driver to blind the victim's defences.

Silver Fox Hackers Chain Three Vulnerable Drivers to Plant ValleyRAT on Japanese Factory
The Chinese crew abused legitimate but flawed Windows drivers to switch off security tools before dropping a remote-access trojan.

Cruciferra: The Malware-Hiding Service Fuelling Attacks on Indian Taxpayers
A China-linked group is paying for a tool called Cruciferra to smuggle remote-access malware onto Windows machines, with fake income tax emails as the entry point.

A Microsoft-Approved Driver Is Helping 'GodDamn' Ransomware Gut US Security Tools
A rebranded criminal gang called Hyadina is using a signed Windows driver to kill antivirus software before locking victims' files. The driver carries a legitimate Microsoft stamp, and nobody knows quite how that happened.

Anubis Affiliates Ride Citrix Bleed 2 Into Enterprise Networks
Ransomware crews are chaining CVE-2025-5777 with RMM tooling and stolen credentials to skip past MFA entirely.

The Gentlemen RaaS Ships an In-House EDR Killer to Affiliates
GentleKiller bundles signed-driver abuse with third-party utilities and a kill list of roughly 400 security processes, handed out as part of the affiliate package.

When the Hardware Isn't There: Coaxing Vulnerable Drivers Into Range
BYOVD research keeps colliding with a stubborn problem, many kernel drivers refuse to talk unless their device is plugged in. New work shows how to make them talk anyway.