Back to Intel

Intel Node

Qilin and Warlock Ransomware Use Vulnerable Drivers to Disable 300+ EDR Tools

highransomware2026-04-06T10:07:00+00:00source excerpt
ransomwaretradecraft

Source excerpt · The upstream feed supplied only part of this article.Read the original source →

Threat actors associated with Qilin and Warlock ransomware operations have been observed using the bring your own vulnerable driver (BYOVD) technique to silence security tools running on compromised hosts, according to findings from Cisco Talos and Trend Micro.

Read Original Source