Frequency
3
occurrences
First Seen
December 9, 2025
Last Seen
December 11, 2025
Exploited in Wild
—
Ransomware Use
—
Public Exploits
—
Attack Vector
—
Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
DeadLock ransomware is being deployed by a financially motivated threat actor using a new loader that utilizes the Bring Your Own Vulnerable Driver (BYOVD) technique. This method disables endpoint detection and response (EDR) processes by exploiting a known vulnerability in a legitimate Baidu Antivi...
Public Exploits
Checking GitHub for proof-of-concept code…
Related Clusters (1)
Related Entities
RansomwareDeadLockT1059.001 - PowerShellT1490 - Inhibit System RecoveryT1562.001 - Disable Or Modify Security ToolsBring Your Own Vulnerable DriverT1021.001 - Remote Desktop ProtocolT1055.012 - Process HollowingT1068 - Exploitation for Privilege EscalationT1112 - Modify RegistryT1548.002 - Bypass User Account ControlWindows