Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
endpoint-security-bypassransomware-group-operationloader-delivery-mechanisminitial-access-method

Malware Families Employing BYOVD and Driver-Based EDR Bypass Techniques

Updated 3mo agoFirst seen Dec 13, 20253 sources

Multiple malware families have adopted advanced techniques to bypass endpoint detection and response (EDR) solutions by leveraging Bring Your Own Vulnerable Driver (BYOVD) attacks and stealthy driver installations. Notably, DeadLock ransomware has been observed exploiting a vulnerable Baidu driver to achieve kernel-level defense bypass, allowing it to disable security products and facilitate ransomware deployment. Similarly, Makop ransomware has evolved to incorporate GuLoader and BYOVD-based EDR killers, specifically targeting networks with exposed Remote Desktop Protocol (RDP) services to gain initial access and evade detection.

In parallel, the ValleyRAT malware family has demonstrated the use of stealthy driver installation methods to circumvent Windows 11 security protections. The public leak of the ValleyRAT builder has expanded its accessibility, enabling a broader range of threat actors to deploy this sophisticated backdoor. These developments highlight a growing trend among threat actors to exploit driver vulnerabilities and kernel-level techniques to undermine modern security controls across various malware campaigns.

Share:
Malware Families Employing BYOVD and Driver-Based EDR Bypass Techniques
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Dec 11, 20256mo ago

Researchers report DeadLock using Baidu driver for kernel-level bypass

A December 2025 report said DeadLock ransomware was deploying a BYOVD-based EDR killer that exploited a Baidu driver to disable defenses at the kernel level. The technique was presented as a defense-evasion method used in the ransomware's operations.

Researchers report Makop using GuLoader and BYOVD EDR killers

A December 2025 report said Makop ransomware had evolved its intrusion chain to use GuLoader and bring-your-own-vulnerable-driver techniques to deploy EDR-killer capabilities. The activity was described as targeting networks exposed through RDP services.

Researchers report ValleyRAT using signed rootkit driver on Windows 11

Analysis published in December 2025 described ValleyRAT using a multi-stage infection chain that installs a validly signed kernel-mode rootkit driver to bypass Windows 11 protections and remove antivirus and EDR drivers from several Chinese security vendors. The report highlighted the malware's modular design and the threat posed by its stealthy driver installation technique.

ValleyRAT activity surges after builder leak

Following the builder's public release, ValleyRAT detections increased sharply, with 85% of detections occurring in the last six months. The surge indicates the malware spread significantly after becoming more widely accessible.

Jun 11, 20251y ago

ValleyRAT builder is publicly leaked

The ValleyRAT (also known as Winos/Winos4.0) builder and its development structure were publicly released, enabling broader use of the malware beyond its original Chinese-speaking operators. This leak complicated attribution and lowered the barrier for additional threat actors to deploy the malware.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

11 LINKEDOpen in app
Organizations
7 linked
Check Point Software TechnologiesTencentQihoo 360Microsoft CorporationBaiduKingsoftHuorong Security
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.