216.73.217.22

Black Basta: Defense Evasion Capability Embedded in Ransomware Payload

· Published 05/02/2026 20:21 · Modified 05/02/2026 20:40

Export JSON

Essential information

Published
05/02/2026 20:21
Modified
05/02/2026 20:40
Tags
2026-02-05 CVE-2025-68947 black basta byovd cardinal defense evasion gotohttp nseckrnl ransomware vulnerable driver
Related entities
1 vulnerabilities (cve), 6 observables, 1 intrusion sets (apt), 2 malware

Description

A recent campaign incorporated a bring-your-own-vulnerable-driver () component within the payload itself, a departure from typical practices. The exploited a vulnerable NsecSoft driver to terminate security processes. This approach, previously seen in Ryuk and Obscura attacks, may indicate a trend towards bundling additional capabilities in payloads. The attack also involved a long dwell time and post-deployment activity using . The group, responsible for , had been quiet following a chat log leak in 2025 but appears to be resuming activities. This development raises questions about future tactics and the potential advantages of embedding capabilities within payloads.

External references