GhostDriver is a tool tracked across 2 threat clusters and 2 intelligence report mentions on ThreatCluster. First observed June 9, 2026; most recent activity June 30, 2026.
Attackers are increasingly using the Bring Your Own Vulnerable Driver (BYOVD) technique to disable antivirus (AV) and endpoint detection and response (EDR) tools. This method exploits flaws in trusted Windows drivers,…
Hacktivist groups 4BID, Hakerskii Kit, and C.A.S. have broadened their attack geography, targeting organizations in Kazakhstan, the UAE, Syria, and Egypt, moving beyond their previous focus on Russian and Belarusian…