Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
endpoint-security-bypassransomware-group-operationransomware-tooling-evolutiondefense-evasion-method

Black Basta Embeds BYOVD Driver Inside Ransomware Payload to Disable EDR

Updated 3mo agoFirst seen Feb 9, 20263 sources

Black Basta ransomware operators have been observed embedding a Bring Your Own Vulnerable Driver (BYOVD) component directly inside the ransomware payload, a shift from the more common approach of deploying an external “EDR killer” tool prior to encryption. The technique abuses a legitimate, signed but vulnerable Windows driver to gain kernel-level privileges and terminate security tooling (AV/EDR) on the victim host, reducing the chance defenders can stop the attack before encryption begins.

Reporting attributes the finding to analysis by Symantec (and the Carbon Black Threat Hunter Team), which described the embedded-driver approach as a notable evolution in Black Basta tradecraft and consistent with broader ransomware trends toward BYOVD-based defense evasion. One account also links the activity to the Cardinal cybercrime group and notes the behavior had not been seen in prior Black Basta campaigns, suggesting either a retooling or a renewed operational tempo that could be adopted by other ransomware families seeking to reliably neutralize endpoint protections.

Share:
Black Basta Embeds BYOVD Driver Inside Ransomware Payload to Disable EDR
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Feb 9, 20264mo ago

Researchers publish targeting and impact details from the Black Basta intrusion

Public reporting said the malware attempted to terminate security tools including Sophos, Symantec, CrowdStrike, and Microsoft Defender processes, then encrypted files with a .locked extension. In the observed case, some files were encrypted, but Symantec's product reportedly continued functioning despite the attack.

Symantec and Carbon Black identify Black Basta's new bundled BYOVD tactic

Symantec analysts and the Carbon Black Threat Hunter Team reported that Black Basta, tracked here as Cardinal, had reemerged with a tactical shift to package BYOVD defense evasion together with ransomware. They said the approach reduces detection opportunities and speeds execution by removing the gap between disabling defenses and encrypting files.

Feb 1, 20265mo ago

Black Basta attack embeds BYOVD driver inside ransomware payload

In a recent intrusion, Black Basta embedded the vulnerable NsecSoft NSecKrnl driver directly into its ransomware payload instead of deploying separate defense-evasion tooling. The bundled BYOVD technique was used to seek kernel-level access and kill security processes before or during encryption.

Jan 1, 20266mo ago

Black Basta loader observed in victim networks weeks before encryption

Researchers reported that a side-loaded loader linked to the intrusion was seen in victim environments weeks before ransomware execution. This suggests the operators may have maintained extended dwell time before launching encryption.

Feb 1, 20251y ago

Police raid alleged Black Basta members in Ukraine

Following the February 2025 chat leak, police reportedly conducted raids against alleged Black Basta members in Ukraine. The action is cited as part of the fallout from the exposure of the group's internal communications.

Black Basta internal chat logs leak and group activity declines

Black Basta's internal chat logs leaked in early 2025, after which the group reportedly went quiet. The leak is described as a major disruption to the operation and a precursor to later developments.

Jan 1, 20251y ago

NSecKrnl driver vulnerability CVE-2025-68947 is disclosed

A vulnerability in NsecSoft's signed NSecKrnl Windows kernel driver, tracked as CVE-2025-68947, was disclosed. The flaw allegedly allows malicious IOCTL requests without proper permission checks, enabling termination of protected processes.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

17 LINKEDOpen in app
Threat actors
2 linked
Malware
2 linked
Affected products
1 linked
Windows
Organizations
11 linked
BroadcomMicrosoft CorporationSophosNsecSoftCrowdStrikeThreat Hunter TeamDark ReadingHuntressOpentextTechTargetAlamy
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.