TGViewer
网络安全笔记 网络安全笔记 @tsecrecord · 7.95K subscribers
Post #1495 2.09K
【📰 文章类型】:威胁情报报告
【⚙️ 技术摘要】:攻击者利用BYOVD技术,通过伪装的Baidu Antivirus驱动(CVE-2024-51324)终止EDR进程,结合PowerShell脚本禁用安全服务、删除卷影副本,并部署DeadLock勒索软件,采用时间密钥的自定义流加密算法加密文件。
【🎯 潜在影响】:企业系统面临数据加密、业务中断、恢复困难及勒索风险,尤其对依赖EDR和备份的组织构成严重威胁。

查看原文
Cisco Talos New BYOVD loader behind DeadLock ransomware attack Cisco Talos has uncovered a new DeadLock ransomware campaign using a previously unknown BYOVD loader to exploit a Baidu Antivirus driver vulnerability, letting threat actors disable EDR defenses and escalate attacks.
  • ❤ 1
More from @tsecrecord
  1. Sep 27, 2026一款本地数字取证/事件响应辅助工具。该浏览器扩展程序会捕获您调查过程中的屏幕截图(例如 Velociraptor、EDR/SIEM 控制面板、Security Onion、Splu…
  2. Sep 20, 2026https://opsectechniques.com/
  3. Aug 27, 2026https://github.com/hypnguyen1209/log4j2-rce
  4. Aug 15, 2026https://telegra.ph/weekly-408-08-14
  5. Jul 6, 2026The Long Watch — Scenario Select https://mr-r3b00t.github.io/org_cyber_attack_sim/
  6. Jun 24, 2026https://techblog.zozo.com/entry/soc-claude-agent#SOC-Agent%E3%81%AE%E8%A8%AD%E8%A8%88
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →