DeadLock Ransomware Employs BYOVD Technique to Bypass Security
First seen 10 Dec 2025, 18:47 UTC
•

•83% similarity
•50.2
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
DeadLock ransomware is being deployed by a financially motivated threat actor using a new loader that utilizes the Bring Your Own Vulnerable Driver (BYOVD) technique. This method disables endpoint detection and response (EDR) processes by exploiting a known vulnerability in a legitimate Baidu Antivirus driver. The attack involves privilege escalation, registry modifications, and custom encryption routines.
ThreatCluster AI
How this analysis works