Tag

#BYOVD

7 stories taggedBYOVD.

A computer screen displaying official-looking Cambodian government and health department documents mixed with property listings, all containing malicious file a
Threat Intelligence

Spark RAT campaign hits Cambodia, using fake government and health notices as bait

Attackers are dropping Spark RAT on Cambodian targets through documents dressed as official government notices, health bulletins and property listings, while using a legitimate security driver to blind the victim's defences.

3 min read
A Japanese factory floor's industrial control systems monitor showing security tools being disabled by malicious driver exploitation, with system alert windows
Threat Intelligence

Silver Fox Hackers Chain Three Vulnerable Drivers to Plant ValleyRAT on Japanese Factory

The Chinese crew abused legitimate but flawed Windows drivers to switch off security tools before dropping a remote-access trojan.

4 min read
An inbox overflowing with official-looking income tax notification emails, with a malware payload invisibly embedded in one highlighted message
Threat Intelligence

Cruciferra: The Malware-Hiding Service Fuelling Attacks on Indian Taxpayers

A China-linked group is paying for a tool called Cruciferra to smuggle remote-access malware onto Windows machines, with fake income tax emails as the entry point.

3 min read
Illustration: a modern server rack with blinking amber and red status lights in a darkened data centre
Ransomware

A Microsoft-Approved Driver Is Helping 'GodDamn' Ransomware Gut US Security Tools

A rebranded criminal gang called Hyadina is using a signed Windows driver to kill antivirus software before locking victims' files. The driver carries a legitimate Microsoft stamp, and nobody knows quite how that happened.

3 min read
Illustration: a dimly lit server rack in a data center with a single amber warning LED glowing on a network appliance
Ransomware

Anubis Affiliates Ride Citrix Bleed 2 Into Enterprise Networks

Ransomware crews are chaining CVE-2025-5777 with RMM tooling and stolen credentials to skip past MFA entirely.

3 min read
Illustration: a darkened server rack with one indicator LED glowing amber while neighboring LEDs are dark
Ransomware

The Gentlemen RaaS Ships an In-House EDR Killer to Affiliates

GentleKiller bundles signed-driver abuse with third-party utilities and a kill list of roughly 400 security processes, handed out as part of the affiliate package.

3 min read
Illustration: a hacker exploiting a Windows driver without hardware, with a focus on code interaction diagrams
Vulnerabilities

When the Hardware Isn't There: Coaxing Vulnerable Drivers Into Range

BYOVD research keeps colliding with a stubborn problem, many kernel drivers refuse to talk unless their device is plugged in. New work shows how to make them talk anyway.

3 min read
© 2026 Threat Vectr