Threats · 162 days ago
A single vulnerable signed driver loaded via DLL side-loading can disable over 300 endpoint detection and response (EDR) kernel drivers across multiple vendors. Qilin and Warlock ransomware operators actively exploit this by using a malicious msimg32.dll to run an in-memory EDR killer that terminates these drivers, delaying ransomware encryption by six days. This attack breaks the assumption that using multiple EDR vendors provides resilience because it targets the shared kernel trust boundary. Even after patching or removing vulnerable drivers, defenders must assume possible persistence and focus on detecting in-memory EDR-killer behaviors and network exfiltration. This represents a critical shift in how kernel-mode drivers can be weaponized to neutralize broad endpoint defenses simultaneously.
1 source covering this story
Qilin and Warlock Ransomware Use Vulnerable Drivers to Disable 300+ EDR Tools
Qilin disables 300+ EDR drivers using BYOVD in 2025 attacks, delaying encryption six days, increasing breach impact.
Part of the PlainSec briefing for 2026-04-07