According to a recent study on endpoint detection and response (EDR) killers, 54 of them abuse a total of 35 vulnerable drivers by adopting a technique called bring your own vulnerable driver (BYOVD).
Since EDR killer programs allow affiliates to disable security software before to the deployment of file-encrypting malware, they have been frequently found in ransomware intrusions. This is done in an effort to avoid being discovered.
According to a report shared with The Hacker News by ESET researcher Jakub Souček, ransomware gangs, particularly those with ransomware-as-a-service (RaaS) programs, regularly create new builds of their encryptors, and making sure that each new build is consistently undetected might take time.
More significantly, because encryptors must change a lot of files quickly, they are naturally quite loud; it is difficult to hide such malware read more about 54 EDR Killers Use BYOVD to Exploit 35 Signed Vulnerable Drivers and Disable Security.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
