216.73.217.22

They Got In Through SonicWall. Then They Tried to Kill Every Security Tool

· Published 04/02/2026 20:22 · Modified 05/02/2026 11:22

Export JSON

Essential information

Published
04/02/2026 20:22
Modified
05/02/2026 11:22
Tags
2026-02-04 byovd driver signature enforcement edr killer encase guidance software kernel driver sonicwall sslvpn
Related entities
2 observables, 14 techniques (mitre), 1 malware

Description

In early February 2026, an intrusion was detected where threat actors exploited compromised credentials for initial network access. The attackers deployed an utilizing a legitimate but revoked forensic driver to terminate security processes from kernel mode. This technique, known as Bring Your Own Vulnerable Driver (), bypasses Windows . The attack was halted before ransomware deployment, but it highlights the growing trend of weaponizing signed, legitimate drivers to disable endpoint security. The intrusion involved aggressive network reconnaissance, deployment of a sophisticated with an encoded payload, and attempts to establish persistence. The case underscores the importance of multi-factor authentication, VPN log monitoring, and implementing Microsoft's recommended driver block rules.

External references