BYOVD Attacks Let Hackers Blind EDR Security Tools via Kernel-Level Exploits
A cyberattack technique called Bring Your Own Vulnerable Driver (BYOVD) is increasingly being used by threat actors to neutralize endpoint security software at the kernel level. Attackers with administrative access install legitimate but vulnerability-ridden signed drivers to gain Ring 0 privileges, bypassing Windows Driver Signature Enforcement. Once inside the kernel, they disable EDR monitoring callbacks, unload security filters, and manipulate kernel objects to hide malicious activity. Real-world cases include the BlackByte ransomware group exploiting MSI Afterburner's RTCore64.sys driver in 2022–2023, and North Korea's Lazarus Group using a vulnerable Dell driver to disable Windows Defender. The technique creates a critical visibility gap where security consoles may falsely report agents as healthy while attackers operate undetected.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in