BYOVD Used to Disable Security: 54 EDR Killers Exploit 35 Vulnerable, Signed Drivers.
Mar 20, 2026 // 11:14 - Niko Dunn


A fresh examination of programs designed to disable endpoint detection and response (EDR) solutions has found that 54 of them exploit a “bring your own vulnerable driver” (BYOVD) method, misusing 35 different vulnerable drivers.

EDR killers are frequently used in ransomware attacks to disable security software before encryption begins, helping the malware avoid being detected.

“Ransomware groups, particularly those using ransomware-as-a-service (RaaS), often create new versions of their encryptors, but ensuring each version goes undetected can take a lot of time,” ESET researcher Jakub Souček said in a report shared with The Hacker News.

“More importantly, encryptors generate a lot of noise by changing numerous files quickly, making it hard to avoid detection.”

EDR killers are separate programs that run before the file lockers, simplifying the lockers and making them easier to update. However, sometimes EDR killers and ransomware are combined into a single program. Reynolds ransomware is an example of this.

Most EDR killers use legitimate but vulnerable drivers to gain high-level access and execute their objectives. Out of the approximately 90 EDR killer tools the Slovakian cybersecurity company identified, the majority use BYOVD because it’s a reliable technique.

“The purpose of a BYOVD attack is to obtain kernel-level privileges, also known as Ring 0,” Bitdefender explains. “At this level, code has full access to the system’s memory and hardware. Because attackers can’t load their own unsigned malicious drivers, they use signed drivers from reputable vendors (like hardware manufacturers or old antivirus versions) that have known vulnerabilities.”

With kernel access, attackers can shut down EDR processes, disable security programs, alter kernel settings, and weaken endpoint protection. They exploit Microsoft’s driver trust system by taking advantage of the fact that the vulnerable driver is legitimate and signed.

BYOVD-based EDR killers are primarily created by three types of attackers –

  • Closed ransomware groups like DeadLock and Warlock that don’t rely on affiliates
  • Attackers modifying existing proof-of-concept code (e.g., SmilingKiller and TfSysMon-Killer)
  • Cybercriminals selling these tools on underground markets as a service (e.g., DemoKiller aka Бафомет, ABYSSWORKER, and CardSpaceKiller) 

ESET also identified script-based tools that employ built-in administrative commands, such as taskkill, net stop, or sc delete, to disrupt the processes and services of security products. Certain versions were found to combine scripting with Windows Safe Mode.

“Since Safe Mode only loads a basic set of the operating system’s components, and security solutions are typically not included, malware has a better chance of disabling protection,” the company said. “However, this activity is very conspicuous because it requires a reboot, which is risky and unreliable in unfamiliar circumstances. Consequently, it’s rarely seen in actual attacks.”

The third category of EDR killers are anti-rootkits, which include legitimate tools such as GMER, HRSword, and PC Hunter, that provide a simple way to shut down protected processes or services. A fourth and emerging category is driverless EDR killers, like EDRSilencer and EDR-Freeze that block outgoing traffic from EDR solutions, causing the programs to become inactive.

“Attackers aren’t investing heavily in making their encryptors undetectable,” ESET stated. “Instead, they are focusing on sophisticated defense-evasion techniques in the user-mode components of EDR killers. This is particularly evident in commercial EDR killers, which often include advanced anti-analysis and anti-detection features.”

To defend against ransomware and EDR killers, blocking commonly abused drivers from loading is crucial. However, because EDR killers are executed in the final stage, immediately before the encryption process, a failure at this point means the attacker can easily use another tool to achieve their goals.

This implies that organizations need multiple layers of security and detection methods to actively monitor, identify, contain, and address threats at every stage of an attack.

“EDR killers remain prevalent because they are inexpensive, consistent, and separate from the encryptor, making them ideal for both encryptor developers who don’t need to worry about making their encryptors undetectable, and affiliates who have a simple and effective tool to disable defenses before encryption,” ESET concluded.

#byovd  #disable  #drivers.  #edr  #exploit  #killers  #news  #security  #signed  #used  #vulnerable   —   News