Researchers and incident responders reported continued abuse of Bring Your Own Vulnerable Driver (BYOVD) techniques to disable endpoint protections, including CrowdStrike Falcon, by loading legitimately signed but flawed Windows kernel drivers. One newly analyzed zero-day driver family included more than 15 variants with valid Microsoft signatures and an IOCTL path such as 0x22E010 that accepted a process ID and invoked ZwOpenProcess and ZwTerminateProcess from kernel mode, allowing attackers to kill protected security processes without alerts. A proof-of-concept dubbed PoisonKiller demonstrated successful termination of the CrowdStrike EDR process through the driver’s symbolic link, underscoring the risk created by trusted but unrevoked third-party drivers.
Separate reporting from Sophos and industry coverage tied the same broader tactic to real intrusions and ransomware activity, including ongoing abuse of Terminator and related tools built around vulnerable Zemana drivers. Attackers used IOCTL flaws to place their own processes on allow lists and then terminate AV and EDR components, while some incidents showed operators switching to alternatives such as AuKill when initial attempts failed. Defenders were urged to combine tamper protection, strict privilege controls, patching, and aggressive blocklisting of unnecessary vulnerable drivers, as signed-driver abuse has spread from advanced actors to commodity ransomware crews and lower-tier criminals.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
Expel reported a ransomware intrusion in which The Gentlemen used a zero-day BYOVD technique abusing the vulnerable Kontron ktapi.sys driver to gain kernel-mode code execution and terminate protected EDR processes before deploying ransomware. The report also disclosed technical details and IOCs, noting the driver was not on public vulnerable-driver blocklists at the time.
A report said Black Basta ransomware operators used bring-your-own-vulnerable-driver techniques to bypass Windows security controls during attacks. The development adds a specific ransomware crew to the list of threat actors operationally abusing vulnerable signed drivers to disable defenses.
A GitHub repository named BYOVD was published describing research use cases for vulnerable driver discovery and reverse-engineering methodology. The project references CVE-2025-52915 and CVE-2025-1055, adding public technical material on BYOVD tradecraft and analysis workflows.
The researcher developed a proof-of-concept exploit called PoisonKiller that successfully used the vulnerable driver's symbolic link to kill the CrowdStrike EDR process from kernel mode. The demonstration highlighted the ongoing risk posed by trusted but unrevoked vulnerable drivers in Windows environments.
A researcher analyzed a previously unknown signed kernel driver used in a BYOVD attack chain and found it could terminate protected security processes, including CrowdStrike Falcon, via an IOCTL handler using ZwOpenProcess and ZwTerminateProcess. The researcher identified more than 15 variants of the malicious driver, all reportedly carrying valid Microsoft signatures and showing no VirusTotal detections.
A GitHub repository named dead-av was published describing a rewritten implementation of BlackSnufkin's BYOVD research that can continuously terminate EDR and antivirus processes. The release adds new public offensive tooling related to vulnerable-driver abuse for disabling endpoint protections.
Cybersecurity Dive reported on ransomware attacks involving a Microsoft-signed driver, underscoring continued operational abuse of signed vulnerable drivers to bypass endpoint protections. The coverage reflected broader industry attention to BYOVD as an active ransomware tradecraft.
A GitHub repository named BadRentdrv2 was published describing a vulnerable driver used for BYOVD that can terminate multiple endpoint detection and antivirus products on both 32-bit and 64-bit Windows systems. The project references CVE-2023-44976 and adds public technical material on offensive abuse of vulnerable drivers to disable security tools.
Sophos published research describing how BYOVD techniques had spread beyond advanced actors, with ransomware operators and lower-tier criminals using Terminator-family tools and vulnerable drivers to kill AV and EDR processes. The report also noted discussion among criminals about custom malicious drivers signed with stolen or leaked certificates.
Sophos reported multiple real-world incidents in late 2023 in which attackers abused vulnerable Zemana-signed drivers and Terminator variants to disable security tools. The cases included activity likely tied to exploitation of vulnerable Citrix applications, a healthcare intrusion involving XMRig delivery and Ternimator, and one intrusion where attackers switched to AuKill after initial attempts failed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
expel.com
Open sourcectrlaltnod.com
Open sourcegithub.com
Open sourcecybersecuritynews.com
Open sourcesophos.com
Open sourcegithub.com
Open sourcecybersecuritydive.com
Open sourcegithub.com
Open sourcescworld.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.