Qilin and Warlock Ransomware Use Vulnerable Drivers to Disable 300+ EDR Tools
According to research from Cisco Talos and Trend Micro, threat actors connected to the Qilin and Warlock ransomware operations have been seen exploiting the bring your own vulnerable driver (BYOVD) approach to mute security solutions operating on affected computers.
Talos' analysis of Qilin attacks revealed that they use a malicious DLL called "msimg32.dll," which starts a multi-stage infection chain to disable endpoint detection and response (EDR) systems. More than 300 EDR drivers from practically every security vendor on the market can be terminated by the DLL when it is activated via DLL side-loading.
According to Talos researchers Takahiro Takeda and Holger Unterbrink, the first stage consists of a PE loader that sets up the execution environment for the EDR killer component. T...



