National Cyber Warfare Foundation (NCWF)

Qilin and Warlock Ransomware Use Vulnerable Drivers to Disable 300+ EDR Tools


0 user ratings
2026-04-06 10:23:39
milo
Blue Team (CND)
Threat actors associated with Qilin and Warlock ransomware operations have been observed using the bring your own vulnerable driver (BYOVD) technique to silence security tools running on compromised hosts, according to findings from Cisco Talos and Trend Micro.
Qilin attacks analyzed by Talos have been found to deploy a malicious DLL named "msimg32.dll,"



Source: TheHackerNews
Source Link: https://thehackernews.com/2026/04/qilin-and-warlock-ransomware-use.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Blue Team (CND)



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.