'GodDamn' Ransomware Uses BYOVD to Smite US Companies
GodDamn ransomware uses a Microsoft-co-signed driver to disable security software.
Run Microsoft?
Get an email when a reviewed story names Microsoft, usually within the hour.
Free. Your list stays private and never appears in a subject line. One click stops it. How Vendor Watch works
Summary
The 'GodDamn' ransomware strain is leveraging a sophisticated technique known as Bring Your Own Vulnerable Driver (BYOVD) to disable security software on victim systems. This is particularly concerning as the attackers are reportedly using a legitimate, Microsoft-co-signed kernel driver, which allows them to bypass security measures more effectively and operate with elevated privileges. This method significantly increases the ransomware's ability to evade detection and execute its payload.
Indicators of Compromise
- malware — GodDamn