Darkreading
Black Basta Ransomware Integrates BYOVD Defense Evasion Technique
First seen 10 Feb 2026, 03:11 UTC
•



+4
•82% similarity
•51.1
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
The Black Basta ransomware gang has incorporated a bring-your-own-vulnerable-driver (BYOVD) defense evasion component within its ransomware payload. This technique, which typically involves separate tools to disable security software, was notably embedded in the ransomware itself during recent attacks. The vulnerable driver identified is the NsecSoft NSecKrnl driver, which poses risks to affected systems.
ThreatCluster AI
Timeline
2026-01-13
CVE-2025-68947 published
2026-02-05
Black Basta attack campaign with BYOVD reported
2026-02-09
Research on Black Basta's ransomware with embedded driver published