T1562.001 - Disable Or Modify Security Tools is a mitre_attack tracked by ThreatCluster, appearing in 1 threat cluster built from 1 intelligence report mention.
T1562.001 - Disable Or Modify Security Tools is a mitre_attack tracked across 1 threat cluster and 1 intelligence report mention on ThreatCluster. First observed December 10, 2025; most recent activity December 10, 2025.
DeadLock ransomware is being deployed by a financially motivated threat actor using a new loader that utilizes the Bring Your Own Vulnerable Driver (BYOVD) technique. This method disables endpoint detection and response…
T1562.001 - Disable Or Modify Security Tools is a mitre_attack tracked by ThreatCluster, appearing in 1 threat cluster built from 1 intelligence report mention.
The most recent intelligence report mentioning T1562.001 - Disable Or Modify Security Tools on ThreatCluster is dated December 10, 2025.
Across ThreatCluster reporting, T1562.001 - Disable Or Modify Security Tools most frequently co-occurs with Ransomware, CVE-2024-51324, DeadLock, T1059.001 - PowerShell, T1490 - Inhibit System Recovery, among 12 tracked related entities.
The most significant recent cluster is “DeadLock Ransomware Employs BYOVD Technique to Bypass Security” (3 articles · Updated December 10, 2025). T1562.001 - Disable Or Modify Security Tools appears across 1 threat cluster in total, listed above with sources.
T1562.001 - Disable Or Modify Security Tools appears in 1 intelligence report mention across 1 deduplicated threat cluster, aggregated from 17,000+ monitored sources.