Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Reynolds Ransomware Uses Vulnerable Driver to Bypass Security

Reynolds Ransomware Uses Vulnerable Driver to Bypass Security

Posted on February 10, 2026 By CWS

Recent discoveries by cybersecurity experts have brought to light a new ransomware variant known as Reynolds. This particular strain incorporates a ‘bring your own vulnerable driver’ (BYOVD) tactic within its payload, aiming to evade detection by compromising endpoint security measures.

Understanding the BYOVD Technique

The BYOVD method involves exploiting legitimate yet flawed driver software to gain higher system privileges. By doing so, ransomware operators can disable Endpoint Detection and Response (EDR) systems, effectively concealing malicious activities. This strategy has been widely used by various ransomware groups over time.

Typically, the BYOVD approach requires a separate tool to be installed before deploying the ransomware. However, researchers from Symantec and the Carbon Black Threat Hunter Team noted that the Reynolds ransomware incorporates the vulnerable driver directly within the payload. The driver in question is the NsecSoft NSecKrnl driver, which has been previously bundled in attacks like the Ryuk ransomware incident in 2020.

Details of the Reynolds Campaign

In its latest campaign, Reynolds ransomware not only deploys the NsecSoft NSecKrnl driver but also terminates critical security processes. This includes those from prominent security vendors such as Avast, CrowdStrike Falcon, and Palo Alto Networks Cortex XDR. The driver exploits a known vulnerability (CVE-2025-68947) to disable these protective measures.

This tactic of embedding the evasion component within the ransomware itself complicates defensive measures. It reduces the need for attackers to separately install additional tools, thus minimizing detection risks. The Reynolds attack campaign also revealed the presence of a suspicious side-loaded loader on targeted networks weeks before the ransomware deployment.

Broader Implications and Recent Trends

The use of BYOVD is favored by attackers due to its effectiveness in evading security systems while utilizing legitimate signed files. This integration of evasion techniques directly into ransomware payloads offers a quieter approach, reducing the visibility of the attack.

Recent developments in ransomware strategies show an increased focus on targeting cloud services and leveraging native cloud features to compromise data. Meanwhile, phishing campaigns and the use of virtual machines for delivering malicious payloads have become more prevalent. These tactics highlight the ongoing evolution and professionalization of ransomware operations.

According to recent data, ransomware activities have surged, with new groups emerging and existing ones forming alliances. The average ransom payment has also seen a notable increase, underscoring the growing financial impact of these cyber threats.

As ransomware tactics become more sophisticated, staying informed and vigilant is crucial for organizations to protect themselves against potential threats.

The Hacker News Tags:BYOVD, Carbon Black, Cybersecurity, EDR, endpoint security, Malware, ransomware tactics, Reynolds ransomware, Symantec, vulnerable drivers

Post navigation

Previous Post: VoidLink Linux Malware: AI-Driven Multi-Cloud Threat
Next Post: Pakistan-Linked Cyber Espionage Targets India’s Defense

Related Posts

Critical LangChain Core Vulnerability Exposes Secrets via Serialization Injection Critical LangChain Core Vulnerability Exposes Secrets via Serialization Injection The Hacker News
Abandoned Sogou Zhuyin Update Server Hijacked, Weaponized in Taiwan Espionage Campaign Abandoned Sogou Zhuyin Update Server Hijacked, Weaponized in Taiwan Espionage Campaign The Hacker News
What the 2025 Gartner® Magic Quadrant™ Reveals What the 2025 Gartner® Magic Quadrant™ Reveals The Hacker News
A walkthrough of the Google Workspace Password Manager A walkthrough of the Google Workspace Password Manager The Hacker News
Samsung Patches CVE-2025-4632 Used to Deploy Mirai Botnet via MagicINFO 9 Exploit Samsung Patches CVE-2025-4632 Used to Deploy Mirai Botnet via MagicINFO 9 Exploit The Hacker News
Guide to Managing AI Usage in Enterprises Guide to Managing AI Usage in Enterprises The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Muddled Libra Exploits VMware vSphere in Cyber Attack
  • Feiniu NAS Devices Targeted in Major Botnet Attack
  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Muddled Libra Exploits VMware vSphere in Cyber Attack
  • Feiniu NAS Devices Targeted in Major Botnet Attack
  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News