HomeSecurityQilin and Warlock ransomware: Using vulnerable drivers to disable EDR

Qilin and Warlock ransomware: Using vulnerable drivers to disable EDR

The Qilin and Warlock ransomware groups have adopted the BYOVD (Bring Your Own Vulnerable Driver) technique to disable security tools on compromised systems, according to new research from Cisco Talos and Trend Micro . The technique allows attackers to neutralize more than 300 EDR (Endpoint Detection and Response) tools from nearly every security vendor on the market.

Qilin and Warlock ransomware EDR

Qilin ransomware

Talos ’ analysis of the Qilin attacks revealed the use of a malicious DLL named “msimg32.dll” that initiates a multi-stage infection chain to disable EDR solutions . The DLL is executed via DLL side-loading and is capable of killing more than 300 EDR drivers from almost every security vendor. Talos researchers Takahiro Takeda and Holger Unterbrink point out that the first stage consists of a PE loader that prepares the execution environment for the EDR killer component.

See also: Warlock Ransomware breached SmarterTools

The secondary payload is embedded within the loader in encrypted form. The DLL loader implements a number of techniques to avoid detection, including neutralizing user-mode hooks and suppressing Event Tracing for Windows (ETW) event logs. It also takes steps to hide control flow and API invocation patterns. This allows the main EDR killer payload to be decrypted, loaded, and executed entirely in memory, going completely unnoticed.

Once launched, the malware uses two drivers:

  • rwdrv.sys , a renamed version of “ ThrottleStop.sys ” that is used to access the system's physical memory and acts as a kernel-mode hardware access layer.
  • hlpdrv.sys , to terminate processes related to more than 300 different EDR drivers belonging to various security solutions .

It is worth noting that both drivers have been used as part of BYOVD carried out in Akira and Makop ransomware.

Qilin ransomware BYOVD technique to disable EDR drivers

Before loading the second driver, the EDR killer component removes the monitoring callbacks installed by EDR, ensuring that process termination can proceed without interference.

See also: Qilin Ransomware combines Linux payload with BYOVD exploit

According to statistics compiled by CYFIRMA and Cynet , Qilin has emerged as the most active ransomware group in recent months, claiming hundreds of victims. The group has been linked to 22 of the 134 ransomware incidents reported in Japan in 2025 , representing 16.4% of all attacks.

Warlock Ransomware and New Attack Techniques

Meanwhile, the Warlock ransomware group (also known as Water Manaul ) continues to exploit unpatched Microsoft SharePoint servers , while upgrading its arsenal for improved persistence, lateral movement, and defense evasion . This includes the use of TightVNC for persistent control and a legitimate but vulnerable NSec driver (“NSecKrnl.sys”) to terminate kernel-level security products.

During Warlock attacks in January 2026 the following tools were observed –

  • PsExec, for lateral movement.
  • RDP Patcher, to facilitate simultaneous RDP sessions.
  • Velociraptor, for command-and-control (C2).
  • Visual Studio Code and Cloudflare Tunnel, for tunneling C2 communications.
  • Yuze, for intranet penetration and creating a reverse proxy connection to the attacker's C2 server via HTTP (port 80), HTTPS (port 443) and DNS (port 53).
  • Rclone, for data extraction.

See also: Qilin Ransomware responsible for Lee Enterprises attack

Qilin and Warlock ransomware: Using vulnerable drivers to disable EDR

To address BYOVD threats, it is recommended to only allow signed drivers from trusted publishers, monitor driver installation events , and maintain a strict patch to keep security software updated.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS