Close Menu
    What's Hot

    Rogue OpenAI agents forced the ‘AI Kill Switch’ bill. Here’s what it aims to do

    Kalshi demands Netflix take down trailer for ‘Prediction Games’ documentary

    Kimbell Royalty Partners: Upgrading To Buy As Growth Accelerates (NYSE:KRP)

    Facebook X (Twitter) Instagram
    Trending
    • Rogue OpenAI agents forced the ‘AI Kill Switch’ bill. Here’s what it aims to do
    • Kalshi demands Netflix take down trailer for ‘Prediction Games’ documentary
    • Kimbell Royalty Partners: Upgrading To Buy As Growth Accelerates (NYSE:KRP)
    • The Hundred: Mitchell Marsh and Dan Lawrence set SunRisers Leeds on course for five-run win over Southern Brave | Cricket News
    • DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts
    • Paxton is trying to cut into Talarico’s lead with Latino voters. It’ll be tough.
    • Conditions for European Wildfires Created by Summer of Extremes
    • AI may finally make ‘women’s work’ valuable. But will women benefit?
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    Qilin and Warlock Ransomware Use Vulnerable Drivers to Disable 300+ EDR Tools

    adminBy adminApril 6, 2026No Comments4 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    Qilin and Warlock Ransomware Use Vulnerable Drivers to Disable 300+ EDR Tools
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananApr 06, 2026Ransomware / Endpoint Security

    Qilin and Warlock Ransomware Use Vulnerable Drivers to Disable 300+ EDR Tools

    Threat actors associated with Qilin and Warlock ransomware operations have been observed using the bring your own vulnerable driver (BYOVD) technique to silence security tools running on compromised hosts, according to findings from Cisco Talos and Trend Micro.

    Qilin attacks analyzed by Talos have been found to deploy a malicious DLL named “msimg32.dll,” which initiates a multi-stage infection chain to disable endpoint detection and response (EDR) solutions. The DLL, launched via DLL side-loading, is capable of terminating more than 300 EDR drivers from almost every security vendor in the market.

    “The first stage consists of a PE loader responsible for preparing the execution environment for the EDR killer component,” Talos researchers Takahiro Takeda and Holger Unterbrink said. “This secondary payload is embedded within the loader in an encrypted form.”

    The DLL loader implements an array of techniques to evade detection. It neutralizes user-mode hooks, suppresses Event Tracing for Windows (ETW) event logs, and takes steps to conceal control flow and API invocation patterns. As a result, it allows the main EDR killer payload to be decrypted, loaded, and executed entirely in memory while entirely flying under the radar.

    Cybersecurity

    Once launched, the malware makes use of two drivers –

    • rwdrv.sys, a renamed version of “ThrottleStop.sys” that’s used to gain access to the system’s physical memory and act as a kernel-mode hardware access layer.
    • hlpdrv.sys, to terminate processes associated with over 300 different EDR drivers belonging to various security solutions.

    It’s worth noting that both drivers have been used as part of BYOVD attacks carried out in conjunction with Akira and Makop ransomware intrusions.

    “Prior to loading the second driver, the EDR killer component unregisters monitoring callbacks established by the EDR, ensuring that process termination can proceed without interference,” Talos said. “It demonstrates the sophisticated tricks the malware is employing to circumvent or completely disable modern EDR protection features on compromised systems.”

    According to statistics compiled by CYFIRMA and Cynet, Qilin has emerged as the most active ransomware group in recent months, claiming hundreds of victims. The group has been linked to 22 out of 134 ransomware incidents that were reported in Japan in 2025, representing 16.4% of all attacks.

    “Qilin primarily relies on stolen credentials to gain initial access,” Talos said. “After successfully breaching a target environment, the group places considerable emphasis on post-compromise activities, allowing it to methodically expand its control and maximize impact.”

    The cybersecurity vendor also noted that ransomware execution occurred on average roughly six days after the initial compromise, highlighting the need for organizations to detect malicious activity at the earliest possible stage and to prevent the deployment of ransomware.

    The disclosure comes as the Warlock (aka Water Manaul) ransomware group continues to exploit unpatched Microsoft SharePoint servers, while updating its toolset for enhanced persistence, lateral movement, and defense evasion.This includes the use of TightVNC for persistent control and a legitimate-but-vulnerable NSec driver (“NSecKrnl.sys”) in a BYOVD attack to terminate security products at the kernel level, replacing the “googleApiUtil64.sys” driver used in prior campaigns.

    Cybersecurity

    Also observed during the course of the Warlock attack in January 2026 were the following tools –

    • PsExec, for lateral movement.
    • RDP Patcher, for facilitating concurrent RDP sessions.
    • Velociraptor, for command-and-control (C2).
    • Visual Studio Code and Cloudflare Tunnel, for tunneling C2 communications.
    • Yuze, for intranet penetration and establishing a reverse proxy connection to the attacker’s C2 server across HTTP (port 80), HTTPS (port 443), and DNS (port 53).
    • Rclone, for data exfiltration.

    To counter BYOVD threats, it’s recommendedto only allow signed drivers from explicitly trusted publishers, monitor driver installation events, and maintain a rigorous patch management schedule for updating security software, specifically those with driver-based components that could be exploited. 

    “Warlock’s reliance on vulnerable drivers to disable security controls requires a multilayered defense focused on kernel integrity,” Trend Micro said. “Thus, organizations must upgrade from basic endpoint protection to enforcing strict driver governance and real-time monitoring of kernel-level activities.”

    Disable drivers EDR Qilin Ransomware Tools vulnerable Warlock
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleTransport Minister Creecy reports 18% drop in Easter road fatalities – The Mail & Guardian
    Next Article Can AI responses be influenced? The SEO industry is trying
    admin
    • Website

    Related Posts

    DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts

    July 25, 2026

    Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

    July 25, 2026

    Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

    July 25, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    Rogue OpenAI agents forced the ‘AI Kill Switch’ bill. Here’s what it aims to do

    Kalshi demands Netflix take down trailer for ‘Prediction Games’ documentary

    Kimbell Royalty Partners: Upgrading To Buy As Growth Accelerates (NYSE:KRP)

    The Hundred: Mitchell Marsh and Dan Lawrence set SunRisers Leeds on course for five-run win over Southern Brave | Cricket News

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by