Reynolds, an emerging ransomware family, has been reported using a Bring Your Own Vulnerable Driver (BYOVD) technique by bundling a legitimate-but-flawed kernel driver (NsecSoft NSecKrnl) directly inside the ransomware payload to evade defenses. The driver vulnerability, tracked as CVE-2025-68947 (reported CVSS 5.7), can be abused to terminate arbitrary processes, enabling Reynolds to disable endpoint security tooling before encryption activity proceeds.
Reporting indicates Reynolds drops the vulnerable NSecKrnl driver and then targets processes associated with multiple security products (including Avast, CrowdStrike Falcon, Palo Alto Networks Cortex XDR, Sophos/HitmanPro.Alert, and Symantec Endpoint Protection). Researchers noted that embedding the BYOVD component within the ransomware payload (rather than deploying a separate pre-ransomware killer tool) has precedent in prior ransomware activity (e.g., Ryuk and Obscura), and the same driver has also been associated with activity attributed to the Silver Fox threat actor in other campaigns.

Get the actors, campaigns, and ATT&CK mapping behind it.
5 events from the most recent confirmed update back to the earliest known activity.
Researchers found the GotoHTTP remote access tool deployed after the ransomware event, with one report specifying it appeared a day after compromise. The finding suggests the operators sought to maintain or regain access following encryption.
Broadcom/Symantec and Carbon Black publicly reported the new Reynolds ransomware family and its unusual design of embedding BYOVD capability directly in the ransomware payload. The disclosure highlighted targeting in the US and UK and warned that integrated defense evasion could make ransomware attacks faster and stealthier.
In the observed intrusions, the Reynolds ransomware payload dropped and loaded the vulnerable signed NsecSoft NSecKrnl driver, then exploited CVE-2025-68947 to terminate EDR and antivirus processes before encrypting systems. Broadcom researchers initially suspected Black Basta due to similar tradecraft, but later confirmed the malware was a distinct ransomware family named Reynolds.
Investigators observed a suspicious side-loaded loader on victim environments weeks before ransomware deployment, indicating an initial access or staging phase. The dwell period reportedly involved reconnaissance and lateral movement before the final attack.
Public reporting cited in the references links the vulnerable NsecSoft NSecKrnl driver (CVE-2025-68947) to earlier Silver Fox activity, where it was used to help deploy ValleyRAT and other post-exploitation tooling. This establishes prior criminal use of the same BYOVD component before Reynolds was identified.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
5 references tracked. Mallory keeps watching after this page renders.
id-ransomware.blogspot.com
Open sourcescworld.com
Open sourcesecurityaffairs.com
Open sourcerescana.com
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.