AuKill is a tool tracked across 2 threat clusters and 2 intelligence report mentions on ThreatCluster. First observed February 9, 2026; most recent activity June 30, 2026.
Attackers are increasingly using the Bring Your Own Vulnerable Driver (BYOVD) technique to disable antivirus (AV) and endpoint detection and response (EDR) tools. This method exploits flaws in trusted Windows drivers,…
The Black Basta ransomware gang has incorporated a bring-your-own-vulnerable-driver (BYOVD) defense evasion component within its ransomware payload. This technique, which typically involves separate tools to disable…