Skip to content
DeadLock Ransomware Employs BYOVD Technique to Bypass Security

DeadLock Ransomware Employs BYOVD Technique to Bypass Security

First seen 10 Dec 2025, 18:47 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 13:27 UTC

DeadLock ransomware is being deployed by a financially motivated threat actor using a new loader that utilizes the Bring Your Own Vulnerable Driver (BYOVD) technique. This method disables endpoint detection and response (EDR) processes by exploiting a known vulnerability in a legitimate Baidu Antivirus driver. The attack involves privilege escalation, registry modifications, and custom encryption routines.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 183d ago How this analysis works

More articles in this cluster (3)

Following this threat?

Track HelloKitty Ransomware Cartel, DeadLock and CVE-2024-51324 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed