Skip to content
Threat Feed

Tag

Byovd

4 briefs RSS
high advisory

Fake LastPass Authenticator Installer Deploys BYOVD Security-Disabling Kernel Driver

Threat actors are distributing a credential-stealing payload via fake GitHub repositories that uses a legitimate Microsoft-signed driver to disable security software via kernel-level process termination.

credential-theft malware byovd windows persistence
1r 3t
high threat

UAT-10147 Deploys SPECTRE Cross-Platform Backdoor

The threat actor UAT-10147 is deploying a sophisticated cross-platform backdoor named SPECTRE, featuring kernel-level rootkits, BYOVD defense evasion, and AI-assisted development artifacts to target IIS and Linux infrastructure.

Internet Information Services UAT-10147 backdoor cross-platform rootkit byovd e-commerce-fraud cybercrime agentic-ai web-exploitation +1
2r 6t 2i updated
high advisory

Threat Actors Disabling AV and EDR Solutions

Threat actors are actively disabling antivirus and EDR solutions through abusing Windows Firewall rules, uninstalling agents, and exploiting vulnerable drivers (BYOVD) to establish persistence, move laterally, and deploy ransomware undetected.

Defender Antivirus +2 defense-evasion privilege-escalation byovd
2r 2t
high advisory

TVicPort64.sys Arbitrary Physical Memory Mapping LPE

The TVicPort64.sys driver, signed by EnTech Taiwan in 2006, is vulnerable to arbitrary physical memory mapping, enabling local privilege escalation on Windows systems.

TVicPort64.sys lpe byovd privilege-escalation signed-driver
2r 1t