2026-06-06 is live. RBL, certificate, and uptime monitoring — now in public beta.

News

New Reynolds Ransomware Integrates BYOVD Evasion Tactics to Neutralize Security Tools


Security analysts have uncovered a fresh ransomware strain named Reynolds that incorporates a “bring your own vulnerable driver” (BYOVD) mechanism directly within its malicious payload to bypass endpoint defenses. This evasion strategy leverages legitimate but compromised driver software to deactivate Endpoint Detection and Response (EDR) systems, concealing subsequent malicious activities.

According to joint research from Symantec and Carbon Black Threat Hunter Team, Reynolds departs from conventional attack sequences where BYOVD tools deploy separately before ransomware execution. Instead, it bundles a vulnerable NsecSoft NSecKrnl driver directly within its payload. This driver exploits a documented flaw (CVE-2025-68947, CVSS 5.7) to terminate security processes from vendors including Avast, CrowdStrike Falcon, Palo Alto Networks Cortex XDR, Sophos (including HitmanPro.Alert), and Symantec Endpoint Protection.

Broadcom researchers note this bundled evasion approach isn’t unprecedented-similar tactics appeared in Ryuk ransomware incidents during 2020 and Obscura attacks in August 2025. The NSecKrnl driver has also been weaponized by the Silver Fox threat group to disable security tools before deploying ValleyRAT malware, continuing a pattern where hackers abuse flawed drivers like truesight.sys and amsdk.sys in BYOVD campaigns.

Integrating evasion capabilities directly into ransomware payloads offers attackers dual advantages: eliminating the need for separate deployment steps makes detection harder while reducing forensic evidence from additional file drops. Investigators additionally observed a suspicious sideloaded loader on victim networks weeks prior to ransomware deployment, followed by GotoHTTP remote access software installation-indicating persistent access attempts.

Recent ransomware developments show broadening tactics:

  • Phishing campaigns distributing GLOBAL GROUP ransomware via LNK files and PowerShell scripts, designed for air-gapped environments without data exfiltration
  • WantToCry attacks exploiting ISPsystem virtual machines with reused hostnames, facilitating payload distribution for LockBit, Qilin, and other ransomware groups
  • DragonForce cartel offering “Company Data Audit” extortion support services including negotiation scripts
  • LockBit 5.0 switching to ChaCha20 encryption across platforms and adding wiper functionality
  • Interlock group exploiting a gaming anti-cheat driver zero-day (CVE-2025-61155) against education-sector targets
  • Increased cloud storage targeting, particularly misconfigured AWS S3 buckets

Ransomware activity surged in 2025 with 4,737 documented attacks, while pure data-theft extortion incidents jumped 23% to 6,182 cases. Coveware reports average ransoms climbed 57% quarter-over-quarter to $591,988 in Q4 2025, driven by high-value settlements. Emerging groups like Sinobi-whose leak site postings surged 306%-join established players like LockBit, which listed secluded organizations in December alone, signaling robust affiliate operations.

First published on February 11, 2026.
Last updated on July 15, 2026.