Security News > 2024 > January > Kasseika Ransomware Using BYOVD Trick to Disarm Security Pre-Encryption

2024-01-24 11:20
The ransomware group known as Kasseika has become the latest to leverage the Bring Your Own Vulnerable Driver (BYOVD) attack to disarm security-related processes on compromised Windows hosts, joining the likes of other groups like Akira, AvosLocker, BlackByte, and RobbinHood. The tactic allows "threat actors to terminate antivirus processes and services for the deployment of ransomware," Trend
News URL
https://thehackernews.com/2024/01/kasseika-ransomware-using-byovd-trick.html
Related news
- New Akira ransomware decryptor cracks encryptions keys using GPUs (source)
- Security shop pwns ransomware gang, passes insider info to authorities (source)
- YES3 Scanner: Open-source S3 security scanner for public access, ransomware protection (source)
- Ransomware spike exposes cracks in cloud security (source)