
🚨 Qilin & Warlock Ransomware Are Killing EDR Tools Before Encryption Begins
🚨 Qilin & Warlock Ransomware Are Killing EDR Tools Before Encryption Begins
Modern ransomware crews aren’t just encrypting files anymore.
They’re dismantling your defenses first.
Threat actors tied to the Qilin and Warlock ransomware operations are now weaponizing vulnerable drivers to silently disable more than 300 endpoint security products before launching ransomware attacks.
And honestly?
That changes the game.
⚠️ The New Battlefield: Kernel-Level Warfare
Researchers from Cisco Talos and Trend Micro uncovered a sophisticated tactic known as:
👉 BYOVD — Bring Your Own Vulnerable Driver
Instead of exploiting the operating system directly, attackers load legitimate but vulnerable signed drivers into Windows.
Once loaded?
💥 They gain kernel-level access
💥 Kill EDR protections
💥 Blind monitoring systems
💥 Operate almost invisibly
🧠 Qilin’s Multi-Stage Attack Chain
Qilin’s attack starts with a malicious DLL:
msimg32.dll
The file is launched through DLL side-loading, helping it appear legitimate.
But under the hood…
👉 It’s an EDR assassin.
🔥 What the Malware Actually Does
The malware chain includes:
🕵️ Evasion Techniques
disables ETW logging
neutralizes user-mode hooks
hides API activity
conceals control flow
Translation?
👉 Your visibility disappears.
💣 Kernel Driver Abuse
Two vulnerable drivers are then loaded:
rwdrv.sys
A renamed version of:
ThrottleStop.sys
Used to:
access physical memory
bypass protections
establish kernel access
hlpdrv.sys
Used to:
terminate over 300 EDR drivers
disable security tools from nearly every major vendor
And yes…
That includes enterprise-grade defenses.
😬 Why This Is Terrifying
Traditional malware tries to avoid EDR.
Qilin?
👉 It kills the EDR first.
Once defenses are blind:
ransomware deployment becomes easier
lateral movement becomes quieter
detection windows collapse fast
Cisco Talos found ransomware execution occurred roughly:
⏳ 6 days after initial compromise
Meaning attackers spend nearly a week:
mapping the network
stealing credentials
expanding control
preparing impact
⚔️ Warlock Is Doing the Same Thing
The Warlock ransomware group is now abusing:
NSecKrnl.sys
Another legitimate-but-vulnerable driver.
And their toolkit is stacked.
🛠️ Warlock’s Offensive Arsenal
Researchers observed the use of:
🔧 PsExec → lateral movement
🖥️ TightVNC → persistence
🌐 Cloudflare Tunnel → covert communications
📡 Velociraptor → command & control
📂 Rclone → data exfiltration
🔄 Yuze → reverse proxy tunneling
💻 Visual Studio Code → stealth operations
Read that again.
Attackers are increasingly using:
👉 legitimate tools
👉 signed software
👉 trusted infrastructure
To look like normal admin activity.
🧬 The Bigger Problem
This isn’t just ransomware evolution.
This is:
👉 defense inversion.
Security products themselves are becoming the attack surface.
If a vulnerable driver exists…
Attackers can weaponize it against you.
🛡️ How Organizations Defend Against BYOVD
Traditional antivirus alone?
Not enough anymore.
Immediate Recommendations:
✅ Restrict driver loading policies
✅ Allow only trusted signed drivers
✅ Monitor kernel-level activity
✅ Watch for suspicious driver installs
✅ Harden EDR tamper protection
✅ Patch vulnerable drivers aggressively
🚨 Security Teams Need Behavioral Detection
Because these attacks blend into normal admin behavior, detection must focus on:
unusual process termination
unsigned driver behavior
ETW suppression
kernel callback removal
suspicious DLL side-loading
privilege escalation patterns
This is where modern EDR/XDR either proves itself…
Or gets switched off.
🎯 Final Takeaway
Qilin and Warlock aren’t smashing through the front door anymore.
They’re:
👉 impersonating IT
👉 weaponizing trust
👉 disabling visibility
👉 then detonating ransomware from the inside
And if your environment still assumes:
“Signed driver = safe”
…you’re playing by rules attackers abandoned a long time ago
