Qilin and Warlock Ransomware Use Vulnerable Drivers to Disable 300+ EDR Tools

Threat actors associated with Qilin and Warlock ransomware operations have been observed using the bring your own vulnerable driver (BYOVD) technique to silence security tools running on compromised hosts, according to findings from Cisco Talos and Trend Micro.
Qilin attacks analyzed by Talos have been found to deploy a malicious DLL named “msimg32.dll,”

Total
0
Shares
Leave a Reply

Your email address will not be published. Required fields are marked *

Previous Post

BKA Identifies REvil Leaders Behind 130 German Ransomware Attacks

Next Post

How LiteLLM Turned Developer Machines Into Credential Vaults for Attackers

Related Posts
Total
0
Share