Cybersecurity

🚨 Qilin & Warlock Ransomware Are Killing EDR Tools Before Encryption Begins

May 14, 20263 min read

🚨 Qilin & Warlock Ransomware Are Killing EDR Tools Before Encryption Begins

Modern ransomware crews aren’t just encrypting files anymore.

They’re dismantling your defenses first.

Threat actors tied to the Qilin and Warlock ransomware operations are now weaponizing vulnerable drivers to silently disable more than 300 endpoint security products before launching ransomware attacks.

And honestly?

That changes the game.


⚠️ The New Battlefield: Kernel-Level Warfare

Researchers from Cisco Talos and Trend Micro uncovered a sophisticated tactic known as:

👉 BYOVD — Bring Your Own Vulnerable Driver

Instead of exploiting the operating system directly, attackers load legitimate but vulnerable signed drivers into Windows.

Once loaded?

💥 They gain kernel-level access
💥 Kill EDR protections
💥 Blind monitoring systems
💥 Operate almost invisibly


🧠 Qilin’s Multi-Stage Attack Chain

Qilin’s attack starts with a malicious DLL:

msimg32.dll

The file is launched through DLL side-loading, helping it appear legitimate.

But under the hood…

👉 It’s an EDR assassin.


🔥 What the Malware Actually Does

The malware chain includes:

🕵️ Evasion Techniques

  • disables ETW logging

  • neutralizes user-mode hooks

  • hides API activity

  • conceals control flow

Translation?

👉 Your visibility disappears.


💣 Kernel Driver Abuse

Two vulnerable drivers are then loaded:

rwdrv.sys

A renamed version of:
ThrottleStop.sys

Used to:

  • access physical memory

  • bypass protections

  • establish kernel access


hlpdrv.sys

Used to:

  • terminate over 300 EDR drivers

  • disable security tools from nearly every major vendor

And yes…

That includes enterprise-grade defenses.


😬 Why This Is Terrifying

Traditional malware tries to avoid EDR.

Qilin?

👉 It kills the EDR first.

Once defenses are blind:

  • ransomware deployment becomes easier

  • lateral movement becomes quieter

  • detection windows collapse fast

Cisco Talos found ransomware execution occurred roughly:

6 days after initial compromise

Meaning attackers spend nearly a week:

  • mapping the network

  • stealing credentials

  • expanding control

  • preparing impact


⚔️ Warlock Is Doing the Same Thing

The Warlock ransomware group is now abusing:

NSecKrnl.sys

Another legitimate-but-vulnerable driver.

And their toolkit is stacked.


🛠️ Warlock’s Offensive Arsenal

Researchers observed the use of:

  • 🔧 PsExec → lateral movement

  • 🖥️ TightVNC → persistence

  • 🌐 Cloudflare Tunnel → covert communications

  • 📡 Velociraptor → command & control

  • 📂 Rclone → data exfiltration

  • 🔄 Yuze → reverse proxy tunneling

  • 💻 Visual Studio Code → stealth operations

Read that again.

Attackers are increasingly using:

👉 legitimate tools
👉 signed software
👉 trusted infrastructure

To look like normal admin activity.


🧬 The Bigger Problem

This isn’t just ransomware evolution.

This is:

👉 defense inversion.

Security products themselves are becoming the attack surface.

If a vulnerable driver exists…

Attackers can weaponize it against you.


🛡️ How Organizations Defend Against BYOVD

Traditional antivirus alone?

Not enough anymore.

Immediate Recommendations:

Restrict driver loading policies
Allow only trusted signed drivers
Monitor kernel-level activity
Watch for suspicious driver installs
Harden EDR tamper protection
Patch vulnerable drivers aggressively


🚨 Security Teams Need Behavioral Detection

Because these attacks blend into normal admin behavior, detection must focus on:

  • unusual process termination

  • unsigned driver behavior

  • ETW suppression

  • kernel callback removal

  • suspicious DLL side-loading

  • privilege escalation patterns

This is where modern EDR/XDR either proves itself…

Or gets switched off.


🎯 Final Takeaway

Qilin and Warlock aren’t smashing through the front door anymore.

They’re:

👉 impersonating IT
👉 weaponizing trust
👉 disabling visibility
👉 then detonating ransomware from the inside

And if your environment still assumes:

“Signed driver = safe”

…you’re playing by rules attackers abandoned a long time ago

Eric Stefanik

Eric Stefanik

Ai Consultant | Best-selling Author | Speaker | Innovator | Leading Cybersecurity Expert

LinkedIn logo icon
Instagram logo icon
Youtube logo icon
Back to Blog