The BYOVD Epidemic: Attackers Weaponize Trusted Windows Drivers to Kill Security Software — Threadlinqs Intelligence
As of 2026-09-02, The BYOVD Epidemic: Attackers Weaponize Trusted Windows Drivers to Kill Security Software is a high-severity ransomware threat attributed to Multiple ransomware-as-a-service affiliates sharing commodity BYOVD tooling (Mixed (China-nexus assessed for the Silver Fox truesight.sys campaign; financially motivated for the RaaS affiliates)), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 29 indicators of compromise.
Threat ID: TL-2026-2297 · Severity: HIGH · Status: ACTIVE · Category: RANSOMWARE
Attribution: Multiple ransomware-as-a-service affiliates sharing commodity BYOVD tooling · Mixed (China-nexus assessed for the Silver Fox truesight.sys campaign; financially motivated for the RaaS affiliates) · FINANCIAL
Bring Your Own Vulnerable Driver (BYOVD) has evolved from a niche technique into a standard defense-evasion stage of the ransomware playbook: attackers with administrator rights load
BYOVD abuses the trust the Windows kernel places in digitally signed drivers: an attacker with local administrator rights loads a legitimate, signed driver that contains an exploitable flaw (arbitrary process termination, arbitrary read/write of kernel memory) instead of writing their own unsigned rootkit. Because the driver's signature validates, the load succeeds even under Driver Signature Enforcement, and the attacker gets Ring 0 code execution to unhook AV/EDR kernel callbacks and force-terminate protected security processes before ransomware deployment.
The technique now spans several distinct lineages of vulnerable/abused drivers. Adlice's RogueKiller anti-rootkit driver, truesight.sys, contains an arbitrary-process-termination flaw in versions below 3.4.0; the legacy 2.0.2 build remains exploitable even after later fixes. Starting mid-2024, a China-nexus cluster tracked as Silver Fox (medium-to-high confidence, per Check Point Research) weaponized this legacy driver at scale, exploiting CVE-2013-3900 (an Authenticode/WinVerifyTrust signature-validation gap) to modify the PE checksum and certificate padding of the driver without invalidating its digital signature. This let them mint over 2,500 distinct signed variants of the same vulnerable driver, defeating hash-based detection while delivering a custom Gh0st RAT variant (HiddenGh0st) from Alibaba Cloud OSS infrastructure. Microsoft's December 17, 2024 Vulnerable Driver Blocklist update targeted this family, but the legacy 2.0.2 build initially evaded it due to certificate-chain differences, and public exploitation tooling (TrueSightKiller) is freely available.
A second lineage abuses an outdated Sysinternals Process Explorer driver (v16.32). The open-source tool AuKill, built on techniques from the 2021 tool Backstab, drops this outdated driver as PROCEXP.SYS into C:\Windows\System32\drivers (alongside the legitimate current PROCEXP152.sys) and uses it to disable EDR/AV processes. At least six AuKill versions have been observed since November 2022; the tool was used ahead of Medusa Locker ransomware deployments in January-February 2023 and a LockBit deployment in February 2023.
A third lineage involves drivers that obtained legitimate Microsoft code-signing rather than exploiting a third-party driver's bug. In December 2022, Mandiant and SentinelOne disclosed the STONESTOP/POORTRY toolkit: POORTRY is a kernel-mode driver that STONESTOP (a user-mode loader) uses to terminate protected security processes and delete files, and it was signed via abuse of the Windows Hardware Compatibility Program (WHCP) after malicious actors compromised legitimate Microsoft Partner Center developer accounts. The toolkit has since been used by UNC3944 (aka Scattered Spider) and multiple ransomware operators including LockBit, BlackCat/ALPHV, Cuba, Medusa, and RansomHub, targeting telecommunications, BPO, MSSP, financial services, cryptocurrency, entertainment, and transportation organizations.
Most recently (April 2026), Cisco Talos and Trend Micro documented Qilin and Warlock ransomware building BYOVD directly into their intrusion chains: Qilin side-loads a malicious msimg32.dll that stages rwdrv.sys (a renamed ThrottleStop.sys providing raw physical-memory access) and hlpdrv.sys, which together terminate processes from over 300 different EDR/AV products after first unregistering kernel callbacks so no alert fires. Warlock combined an NSec vulnerable driver with the TightVNC remote-access tool in BYOVD intrusions against vulnerable on-premises Microsoft SharePoint servers. GhostDriver, a further open-source automation tool, similarly drives IOCTLs against a hardcoded, actively maintained list of 300+ targeted security products. Symantec's Threat Hunter Team (June 2026) frames the collective pattern as hundreds of exploitable drivers already in circulation, with publicly known bypasses for kernel hardening features (KASLR, HVCI, KCFG) meaning the mitigations most organizations rely on
Target sectors: telecoms, business process outsourcing, managed service providers, financial services, cryptocurrency, entertainment, transport, health
Target regions: Asia-Pacific, North America, Europe, Global
Timeline
- Backstab, the open-source EDR-killing tool later adapted into AuKill, is published.
- Earliest known AuKill (v1) sample compiled, abusing the outdated Process Explorer v16.32 driver (PROCEXP.SYS).
- Mandiant and SentinelOne disclose the STONESTOP/POORTRY BYOVD toolkit and the Windows Hardware Compatibility Program signing loophole abused by UNC3944 to get POORTRY Microsoft-signed.
- AuKill used to disable EDR ahead of Medusa Locker ransomware deployments (January-February 2023 incidents).
- AuKill used to disable EDR immediately prior to a LockBit ransomware deployment.
- Sophos publishes technical research on AuKill, cataloguing six driver-dropper versions observed since November 2022.
- Silver Fox begins large-scale exploitation of the legacy truesight.sys 2.0.2 driver to deliver a Gh0st RAT variant (HiddenGh0st), per Check Point telemetry.
- Silver Fox shifts to generating thousands of checksum/signature-preserving truesight.sys variants (ultimately 2,500+ unique hashes) via CVE-2013-3900 to evade hash-based detection.
- Microsoft updates the Vulnerable Driver Blocklist to block the modified truesight.sys variant family.
- Check Point Research and The Hacker News publish findings on the 2,500+ truesight.sys driver-variant campaign, noting the legacy 2.0.2 build initially evaded the December 2024 blocklist update.
- Cisco Talos and Trend Micro document Qilin and Warlock ransomware BYOVD chains: msimg32.dll/rwdrv.sys/hlpdrv.sys terminating 300+ EDR products, and Warlock's NSec driver + TightVNC intrusion against on-prem SharePoint.
- Symantec/Broadcom Threat Hunter Team publishes 'The BYOVD Epidemic,' documenting BYOVD's evolution into a standard component of the ransomware playbook.
Detections & IOCs
As of 2026-09-03, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 29 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
RANSOMWARE, HIGH, threat intelligence, cybersecurity, CVE-2013-3900, T1588.002, T1588.003, T1204.002, T1569.002, T1543.003, T1685, T1014, T1036.005, T1027, T1553.002