Bring Your Own Vulnerable Driver (BYOVD) is a MITRE ATT&CK technique in which adversaries load a vulnerable or unsigned driver to run code in kernel space, enabling privilege escalation and stealth.
Bring Your Own Vulnerable Driver is a mitre_attack tracked across 1 threat cluster and 1 intelligence report mention on ThreatCluster. First observed December 11, 2025; most recent activity December 11, 2025.
Bring Your Own Vulnerable Driver (BYOVD) is a MITRE ATT&CK technique in which adversaries load a vulnerable or unsigned driver to run code in kernel space, enabling privilege escalation and stealth. It is significant because kernel-level execution allows attackers to bypass many endpoint protections and conceal malicious activity, a tactic leveraged by ransomware such as DeadLock to evade detection and enhance impact.
DeadLock ransomware is being deployed by a financially motivated threat actor using a new loader that utilizes the Bring Your Own Vulnerable Driver (BYOVD) technique. This method disables endpoint detection and response…
Bring Your Own Vulnerable Driver (BYOVD) is a MITRE ATT&CK technique in which adversaries load a vulnerable or unsigned driver to run code in kernel space, enabling privilege escalation and stealth.
The most recent intelligence report mentioning Bring Your Own Vulnerable Driver on ThreatCluster is dated December 11, 2025.
Across ThreatCluster reporting, Bring Your Own Vulnerable Driver most frequently co-occurs with Ransomware, CVE-2024-51324, DeadLock, Baidu Antivirus, Windows, among 6 tracked related entities.
The most significant recent cluster is “DeadLock Ransomware Employs BYOVD Technique to Bypass Security” (3 articles · Updated December 10, 2025). Bring Your Own Vulnerable Driver appears across 1 threat cluster in total, listed above with sources.
Bring Your Own Vulnerable Driver appears in 1 intelligence report mention across 1 deduplicated threat cluster, aggregated from 17,000+ monitored sources.