< Back to all clusters
[TECHNOLOGY] · 2 sources

Ransomware leverages vulnerable drivers and remote encryption to bypass defenses

The Warlock ransomware family, also known as Storm‑2603, has adopted a "Bring Your Own Vulnerable Driver" (BYOVD) approach, loading digitally signed but vulnerable drivers to gain kernel‑level privileges and disable endpoint detection and response tools. Cisco Talos and TrendMicro report that Warlock and related strains can terminate more than 300 EDR drivers across major vendors. A 2026 breach of SmarterTools illustrated how a single unpatched shadow VM can provide entry for such attacks, highlighting the risk of unmanaged assets and the need for comprehensive asset discovery.

The broader ransomware landscape continues to rely on remote encryption, with recent Microsoft and Sophos data showing that 70% of successful attacks involve encrypting data from unmanaged devices, up from 60% in 2023. Sophos’s CryptoGuard technology counters this by monitoring file‑system operations in real time, blocking encryption activity without relying on signatures or cloud analytics. The approach has detected multiple ransomware families on first encounter.

Mitigation recommendations include strict driver blocklisting, zero‑trust asset inventory, kernel‑level monitoring, and network segmentation to isolate critical servers. Deploying data‑layer protection such as CryptoGuard can further reduce the risk of successful ransomware encryption.