Skip to content
Black Basta Ransomware Integrates BYOVD Defense Evasion Technique

Black Basta Ransomware Integrates BYOVD Defense Evasion Technique

First seen 10 Feb 2026, 03:11 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 13:27 UTC

The Black Basta ransomware gang has incorporated a bring-your-own-vulnerable-driver (BYOVD) defense evasion component within its ransomware payload. This technique, which typically involves separate tools to disable security software, was notably embedded in the ransomware itself during recent attacks. The vulnerable driver identified is the NsecSoft NSecKrnl driver, which poses risks to affected systems.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 182d ago How this analysis works

Timeline

2026-01-13
CVE-2025-68947 published
2026-02-05
Black Basta attack campaign with BYOVD reported
2026-02-09
Research on Black Basta's ransomware with embedded driver published

More articles in this cluster (9)

Following this threat?

Track Black Basta, Cardinal and Qakbot in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed