threat-intel SilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRAT The Chinese cybercrime group Silver Fox is targeting Japanese manufacturers using a sophisticated Bring Your Own Vulnerable Driver (BYOVD) attack chain to deploy ValleyRAT, a Gh0st RAT variant. They utilize a layered approach incorporating new drivers – BootRepair.sys, EnPortv.sys, and wsftprm.sys – alongside DLL side-… The Hacker News · Jul 30, 2026 High SOCHbyovddll side-loadingntdll unhooking
ransomware GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses The GodDamn ransomware family, a rebrand of Beast ransomware (originally based on Monster), is utilizing a newly discovered malicious driver called PoisonX to disable endpoint defenses and gain access to systems. Threat… The Hacker News · Jul 9, 2026 High ransomwarepoisonxbyovd
threat-intel 'GodDamn' Ransomware Uses BYOVD to Smite US Companies The ransomware group Hyadina, operating under the name "GodDamn," is leveraging a Microsoft-approved, malicious kernel driver – dubbed "PoisonX" – to infiltrate US organizations and deploy its ransomware. They utilize a… Dark Reading · Jul 9, 2026 High RUransomwaredriverbyovd
ransomware The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes The Gentlemen ransomware-as-a-service (RaaS) operation is utilizing a sophisticated suite of EDR-terminating tools, centered around the GentleKiller framework, to disable security defenses before deploying ransomware. Th… The Hacker News · Jun 19, 2026 High RUSOWEransomware-as-a-serviceedr-killingbyovd
ransomware DragonForce Hackers Abuse Microsoft Teams Relays to Hide Backdoor.Turn C2 Traffic A U.S. services firm was targeted by the DragonForce ransomware group, who utilized a custom Go-based RAT, Backdoor.Turn, to conceal C2 traffic within Microsoft Teams relay infrastructure. The attackers leveraged a BYOVD… The Hacker News · Jun 18, 2026 High CVE-2023-52271CVE-2025-61155CVE-2025-1055USturnbyovdghost calls
ransomware Ransomware gang abuses Microsoft Teams relays to hide malicious traffic DragonForce ransomware utilized a custom malware, Backdoor.Turn, to conceal command-and-control traffic by leveraging Microsoft Teams’ TURN protocol. This technique allowed the attackers to bypass traditional network def… BleepingComputer · Jun 16, 2026 High CVE-2023-52271CVE-2025-61155CVE-2025-1055USteamsturnrat
threat-intel Making Vulnerable Drivers Exploitable Without Hardware - The BYOVD Perspective This article details a technique for evaluating the exploitability of Windows kernel mode drivers, focusing on the potential for BYOVD (Bring Your Own Vulnerability Driver) attacks. It highlights how vulnerabilities in d… The Hacker News · May 22, 2026 Medium USdriverbyovdkernel mode