216.73.216.233

New BYOVD loader behind DeadLock ransomware attack

· Published 10/12/2025 09:43 · Modified 21/12/2025 18:54

Export JSON

Essential information

Published
10/12/2025 09:43
Modified
21/12/2025 18:54
Tags
2025-12-10 CVE-2024-51324 byovd deadlock edr evasion ransomware
Related entities
1 vulnerabilities (cve), 5 observables, 1 intrusion sets (apt), 15 techniques (mitre), 1 malware

Description

A new loader exploiting a Baidu Antivirus driver vulnerability () has been discovered in connection with attacks. The threat actor uses the Bring Your Own Vulnerable Driver () technique to terminate endpoint detection and response processes. A PowerShell script is employed to bypass User Account Control, disable Windows Defender, terminate security services, and delete volume shadow copies. targets Windows machines using a custom stream cipher encryption algorithm with time-based cryptographic keys. The attack involves initial access through compromised accounts, system registry modifications, remote access establishment, reconnaissance, lateral movement, and defense impairment. The 's sophisticated encryption process includes recursive directory traversal, memory-mapped file I/O, and multi-threaded processing.

External references