Qilin and Warlock Ransomware Use Vulnerable Drivers to Disable 300+ EDR Tools


Certains articles de veille peuvent faire l'objet de traduction automatique.


Qilin and Warlock Ransomware Use Vulnerable Drivers to Disable 300+ EDR Tools

Threat actors associated with Qilin and Warlock ransomware operations have been observed using the bring your own vulnerable driver (BYOVD) technique to silence security tools running on compromised hosts, according to findings from Cisco Talos and Trend Micro.
Qilin attacks analyzed by Talos have been found to deploy a malicious DLL named « msimg32.dll, »

Source : https://thehackernews.com/2026/04/qilin-and-warlock-ransomware-use.html

Publications similaires

avril 6, 2026
0 0 votes
Évaluation de l'article

Ce site utilise Akismet pour réduire les indésirables. Découvrez comment les données de vos commentaires sont traitées.

0 Commentaires
plus vieux
nouveaux plus votés