The Qilin and Warlock ransomware groups have adopted the BYOVD (Bring Your Own Vulnerable Driver) technique to disable security tools on compromised systems, according to new research from Cisco Talos and Trend Micro . The technique allows attackers to neutralize more than 300 EDR (Endpoint Detection and Response) tools from nearly every security vendor on the market.

Qilin ransomware
Talos ’ analysis of the Qilin attacks revealed the use of a malicious DLL named “msimg32.dll” that initiates a multi-stage infection chain to disable EDR solutions . The DLL is executed via DLL side-loading and is capable of killing more than 300 EDR drivers from almost every security vendor. Talos researchers Takahiro Takeda and Holger Unterbrink point out that the first stage consists of a PE loader that prepares the execution environment for the EDR killer component.
See also: Warlock Ransomware breached SmarterTools
The secondary payload is embedded within the loader in encrypted form. The DLL loader implements a number of techniques to avoid detection, including neutralizing user-mode hooks and suppressing Event Tracing for Windows (ETW) event logs. It also takes steps to hide control flow and API invocation patterns. This allows the main EDR killer payload to be decrypted, loaded, and executed entirely in memory, going completely unnoticed.
Once launched, the malware uses two drivers:
- rwdrv.sys , a renamed version of “ ThrottleStop.sys ” that is used to access the system's physical memory and acts as a kernel-mode hardware access layer.
- hlpdrv.sys , to terminate processes related to more than 300 different EDR drivers belonging to various security solutions .
It is worth noting that both drivers have been used as part of BYOVD carried out in Akira and Makop ransomware.

Before loading the second driver, the EDR killer component removes the monitoring callbacks installed by EDR, ensuring that process termination can proceed without interference.
See also: Qilin Ransomware combines Linux payload with BYOVD exploit
According to statistics compiled by CYFIRMA and Cynet , Qilin has emerged as the most active ransomware group in recent months, claiming hundreds of victims. The group has been linked to 22 of the 134 ransomware incidents reported in Japan in 2025 , representing 16.4% of all attacks.
Warlock Ransomware and New Attack Techniques
Meanwhile, the Warlock ransomware group (also known as Water Manaul ) continues to exploit unpatched Microsoft SharePoint servers , while upgrading its arsenal for improved persistence, lateral movement, and defense evasion . This includes the use of TightVNC for persistent control and a legitimate but vulnerable NSec driver (“NSecKrnl.sys”) to terminate kernel-level security products.
During Warlock attacks in January 2026 the following tools were observed –
- PsExec, for lateral movement.
- RDP Patcher, to facilitate simultaneous RDP sessions.
- Velociraptor, for command-and-control (C2).
- Visual Studio Code and Cloudflare Tunnel, for tunneling C2 communications.
- Yuze, for intranet penetration and creating a reverse proxy connection to the attacker's C2 server via HTTP (port 80), HTTPS (port 443) and DNS (port 53).
- Rclone, for data extraction.
See also: Qilin Ransomware responsible for Lee Enterprises attack

To address BYOVD threats, it is recommended to only allow signed drivers from trusted publishers, monitor driver installation events , and maintain a strict patch to keep security software updated.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
