Ransomware operators are using Bring Your Own Vulnerable Driver (BYOVD) attacks to load legitimately signed but flawed Windows kernel drivers, gain ring-0 access, and terminate security products protected by Protected Process Light (PPL). Reported examples include the WatchDog Antimalware v1.1.100 and eb kernel drivers, whose unauthenticated IOCTL interfaces can reportedly be abused to kill protected processes. Qilin's Killer Ultra and RansomHub's EDRKillShifter have used the technique through user-mode launchers that drop, load, and control vulnerable drivers.
Defenders should detect the sequence of suspicious driver drops, rapid driver installation or loading, low-prevalence driver hashes, and subsequent termination of endpoint-security processes. Organizations should inventory and baseline deployed drivers, enforce Windows Defender Application Control (WDAC) driver policies, enable Microsoft’s Vulnerable Driver Blocklist and HVCI, maintain EDR tamper protection, and restrict administrative privileges to reduce exposure to known vulnerable drivers, including those catalogued by LOLDrivers.

Get the actors, campaigns, and ATT&CK mapping behind it.
1 event from the most recent confirmed update back to the earliest known activity.
Criminal-market listings advertised EDR and antivirus killing tools claiming kernel-level operation and, in some cases, source-code availability. The listings appeared from December 2025 through February 2026.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.