Darkreading Black Basta Ransomware Integrates BYOVD Defense Evasion Technique
Article Content
Browse articles
The Black Basta ransomware gang has incorporated a bring-your-own-vulnerable-driver (BYOVD) defense evasion component within its ransomware payload. This technique, which typically involves separate tools to disable security software, was notably embedded in the ransomware itself during recent attacks. The vulnerable driver identified is the NsecSoft NSecKrnl driver, which poses risks to affected systems.
Ask AI about this cluster
Answers cite the sources they use
Updated 182d ago How this analysis works
Timeline
2026-01-13
CVE-2025-68947 published
2026-02-05
Black Basta attack campaign with BYOVD reported
2026-02-09
Research on Black Basta's ransomware with embedded driver published
More articles in this cluster (9)
Following this threat?
Track Black Basta, Cardinal and Qakbot in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Node.js Exploited in Ransomware Attacks Using EtherHiding Technique Since February 2026, threat actors have been exploiting the trusted Node.js runtime to deploy malicious payloads in targeted attacks against government departments, technology companies, and hotels. The technique leverages node.exe, a legitimate and signed developer tool, allowing attackers to run interpreted scripts…
Qilin Ransomware Targets Retelit, Major Telecom Provider in Italy The Qilin ransomware group has reportedly targeted Retelit SpA, a leading telecommunications operator in Italy. This attack is part of a broader campaign that has seen a significant increase in ransomware incidents attributed to Qilin since the start of 2026. The group exploits known vulnerabilities, particularly in…