Qilin Ransomware and the Hidden Dangers of BYOVD

July 31, 2025, 3:22 p.m.

Description

This analysis examines a recent incident involving Qilin ransomware, highlighting the evolving tactics of cybercriminals to evade Endpoint Detection and Response (EDR) systems. The attackers utilized a previously unknown driver, TPwSav.sys, to disable EDR measures through a technique known as bring-your-own-vulnerable-driver (BYOVD). The report details the entire attack chain, from initial compromise using stolen credentials to the final attempt at deploying ransomware. It emphasizes how rapid isolation of impacted systems and a layered security approach thwarted the attackers. The analysis also provides background on Qilin ransomware, its operation as a ransomware-as-a-service (RaaS), and its targeting patterns. The technical breakdown includes an examination of the EDR bypass technique and the customized version of the EDRSandblast tool used in the attack.

Date

  • Created: July 31, 2025, 1:13 p.m.
  • Published: July 31, 2025, 1:13 p.m.
  • Modified: July 31, 2025, 3:22 p.m.

Indicators

  • 3dfae7b23f6d1fe6e37a19de0e3b1f39249d146a1d21102dcc37861d337a0633
  • 08224e4c619c7bbae1852d3a2d8dc1b7eb90d65bba9b73500ef7118af98e7e05
  • aeddd8240c09777a84bb24b5be98e9f5465dc7638bec41fb67bbc209c3960ae1
  • d3af11d6bb6382717bf7b6a3aceada24f42f49a9489811a66505e03dd76fd1af
  • 011df46e94218cbb2f0b8da13ab3cec397246fdc63436e58b1bf597550a647f6
  • 31.192.107.144
  • 216.120.203.26

Attack Patterns

Additional Informations

  • Construction
  • United States of America