PoisonX Driver: Malicious Kernel Driver Signed by Microsoft
PoisonX is a malicious kernel driver used in BYOVD attacks to disable security software. It was signed by Microsoft, allowing it to…
PoisonX is a malicious kernel driver used in BYOVD attacks to disable security software. It was signed by Microsoft, allowing it to…
ABYSSWORKER is a custom-built malicious driver used in BYOVD attacks, previously observed in Medusa ransomware incidents.
Huawei is a Chinese technology company whose driver (HWAuidoOs2Ec.sys) was used in a BYOVD attack by DragonForce.
CVE-2023-52271 is a vulnerability associated with the driver wsftprm.sys used in BYOVD attacks by DragonForce.
CVE-2025-61155 is a vulnerability associated with the driver GameDriverX64.sys used in BYOVD attacks by DragonForce.
CVE-2025-1055 is a vulnerability associated with the driver K7RKScan.sys used in BYOVD attacks by DragonForce.