Diamond Member ThaHaka 0 Posted 1 hour ago Diamond Member Share Posted 1 hour ago This is the hidden content, please Sign In or Sign Up Threat actors associated with Qilin and Warlock ransomware operations have been observed using the bring your own vulnerable driver (BYOVD) technique to silence security tools running on compromised hosts, according to findings from Cisco Talos and Trend Micro. Qilin attacks analyzed by Talos have been found to deploy a malicious DLL named "msimg32.dll," This is the hidden content, please Sign In or Sign Up 0 Quote Link to comment https://hopzone.eu/forums/topic/307858-h4ckn3wsqilin-and-warlock-ransomware-use-vulnerable-drivers-to-disable-300-edr-tools/ Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.