Partner Content

BlackByte Ransomware Gang Adds Sophisticated “Bring Your Own Driver” Technique to Bypass More Than 1,000 Drivers Used by Industry Wide Endpoint Detection and Response (EDR) Products, Sophos Finds

Photo Credit: 123RF.com

Photo Credit: 123RF.com

Sophos, a global leader in next-generation cybersecurity, today announced that BlackByte, one of the newer, “heavy-hitter” ransomware gangs, has added a sophisticated “Bring Your Own Driver” technique to bypass more than 1,000 drivers used by industry Endpoint Detection and Response (EDR) products. Sophos details the attack tactics, techniques and procedures (TTPs) in the report, “Remove all the Callbacks – BlackByte Ransomware Disables EDR via RTCore64.sys Abuse.

To Read the Full Story