DeadLock Ransomware Employs BYOVD Technique to Bypass Security
Article Content
Browse articles
DeadLock ransomware is being deployed by a financially motivated threat actor using a new loader that utilizes the Bring Your Own Vulnerable Driver (BYOVD) technique. This method disables endpoint detection and response (EDR) processes by exploiting a known vulnerability in a legitimate Baidu Antivirus driver. The attack involves privilege escalation, registry modifications, and custom encryption routines.
Ask AI about this cluster
Answers cite the sources they use
Updated 183d ago How this analysis works
More articles in this cluster (3)
Following this threat?
Track HelloKitty Ransomware Cartel, DeadLock and CVE-2024-51324 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Nigeria and South Africa Face Surge in Cyberattacks Amid Ransomware Threats In July 2026, Nigeria recorded an alarming average of 4,975 cyberattacks per organization weekly, marking an 87% surge in ransomware incidents. This data, reported by Check Point Research, places Nigeria among the most targeted countries globally. South Africa has emerged as a significant target, accounting for 92% of…
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…