As cited
Copy frozen at (site build).
ransomware
'GodDamn' Ransomware Uses BYOVD to Smite US Companies
A malicious kernel driver co-signed by Microsoft is being exploited in ransomware attacks targeting US companies to disable security software. The driver is associated with a ransomware variant named GodDamn. Attackers are leveraging this bring-your-own-vulnerable-driver (BYOVD) technique to gain kernel-level access and bypass endpoint protection.
Why it matters: US organizations running vulnerable endpoint protection are at immediate risk from ransomware operators who can disable defenses using Microsoft-signed drivers; security teams should audit kernel driver trust policies and update or replace affected security software.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
ransomware
'GodDamn' Ransomware Uses BYOVD to Smite US Companies
A malicious kernel driver co-signed by Microsoft is being exploited in ransomware attacks targeting US companies to disable security software. The driver is associated with a ransomware variant named GodDamn. Attackers are leveraging this bring-your-own-vulnerable-driver (BYOVD) technique to gain kernel-level access and bypass endpoint protection.
Why it matters: US organizations running vulnerable endpoint protection are at immediate risk from ransomware operators who can disable defenses using Microsoft-signed drivers; security teams should audit kernel driver trust policies and update or replace affected security software.
- Source published
- First seen by Cybersecurity Tracker