DeadLock Ransomware Strikes Again, Using a Weaponized Driver to Slip Past Windows Defenses

Listen to this Post

Featured Image

Introduction

The cybersecurity world is no stranger to ransomware, yet every few months a new strain arrives with enough sophistication to rattle even the most prepared organizations. DeadLock is one of those threats, a rapidly evolving ransomware family now armed with an unusually stealthy delivery chain that abuses a vulnerable Baidu Antivirus driver to neutralize endpoint defenses. Cisco Talos researchers have traced this latest campaign to a financially motivated group that operates with surgical precision, leaving defenders with little time to react. What follows is a detailed narrative of how the attack unfolds, why it bypasses multiple layers of protection, and what makes DeadLock a rising force in the global ransomware economy.

Main Summary

A financially driven ransomware operator has deployed a new DeadLock variant that exhibits advanced evasion abilities designed to quietly compromise Windows environments. Cisco Talos analysts uncovered that the threat actor relies on the Bring Your Own Vulnerable Driver technique, a method that abuses legitimate but flawed drivers to gain kernel level control. In this case, the attackers weaponized a vulnerable Baidu Antivirus driver cataloged as CVE-2024-51324. By doing so, the actor bypassed EDR protections, terminated security processes, and executed the ransomware payload without detection.

The intrusion begins with the delivery of a custom loader known as EDRGay.exe. This loader silently drops a vulnerable driver named BdApiUtil.sys, disguised as DriverGay.sys, into the victim’s Videos folder. The flaw in this driver is tied to improper privilege management, a weakness that grants unprivileged users the ability to terminate system processes at the highest kernel layer. Once in place, the loader activates the driver using the Windows CreateFile API and exploits the IOCTL 0x800024b4 command. This allows the malware to leverage the ZwTerminateProcess system call to kill running EDR and antivirus services. The entire sequence aligns with MITRE technique T1211, a strategy used by sophisticated actors to exploit defensive systems directly.

With endpoint protections dismantled, the attackers shift to escalating their permissions. They execute a PowerShell script crafted to bypass User Account Control, disable Windows Defender, and eliminate system recovery options. This script purges shadow copies, ensuring victims have no immediate method to restore their data. It also alters startup configurations for essential services, allowing the attackers to maintain persistence across system reboots. These modifications reinforce control and prepare the system for the ransomware execution phase.

The DeadLock payload itself is a C++ based encryptor compiled in mid 2025. This version uses a custom stream cipher that generates cryptographic seeds derived from system time, allowing fast and stable encryption while keeping systems responsive enough for ransom negotiation. Once files are locked, they receive the extension .dlock along with a distinctive hexadecimal identifier that helps attackers map victims during negotiations.

The ransomware terminates many processes associated with defensive tools, remote management utilities, database engines, and backup applications. Platforms such as Veeam, Acronis, Veritas, and SQL Server are among the targeted services. However, the malware avoids disabling essential Windows components to ensure the operating system remains functional after encryption, a common trait among modern extortion focused groups.

Investigators also confirmed that initial access was achieved through compromised accounts. Once inside, attackers enabled RDP connections and installed AnyDesk to maintain long term remote access channels. They manipulated Windows Defender using SystemSettingsAdminFlows.exe to disable features like real time monitoring and cloud based protection. What sets the group apart is their operational approach. Unlike traditional ransomware syndicates that run public extortion platforms, DeadLock operators do not maintain leak sites. Instead, they direct victims to communicate exclusively using Session messenger, an encrypted communications tool preferred for anonymous negotiation.

Cisco Talos urges organizations to update their defenses against Bring Your Own Vulnerable Driver attacks, proactively block known vulnerable drivers, enable multi factor authentication, and monitor for suspicious PowerShell activity. Updated Snort rules and ClamAV signatures have been released to help networks identify DeadLock’s infrastructure and artifacts.

What Undercode Say:

DeadLock represents a concerning shift in ransomware methodology because it merges traditional extortion tactics with low level exploitation normally seen in advanced persistent threat operations. This combination of stealth and force allows attackers to dismantle security controls without triggering alarms. Any ransomware group that begins operating at the kernel layer becomes exponentially more dangerous because traditional endpoint defenses are designed to operate above that layer. When the defensive tools rely on user space monitoring, yet the attacker is already working from the kernel, the defender loses the advantage instantly.

The presence of a vulnerable Baidu driver is more than a technical detail. It highlights a recurring industry problem where outdated or abandoned software components become permanent liabilities. Attackers do not need to find new vulnerabilities when a trove of old drivers remains exploitable. DeadLock’s operators weaponize these forgotten components with precision, using them to execute an EDR kill chain that no commercial product can easily block without explicit driver restriction policies.

Another notable angle is the attackers’ preference for encrypted communication through Session rather than traditional dark web leak sites. This creates two strategic outcomes. First, it deprives researchers of visibility into victim lists, making it harder to track the group’s activity. Second, it adds psychological pressure on victims because the absence of a public shaming mechanism means negotiations occur privately, controlled entirely by the attackers.

The choice of a custom stream cipher is also unusual. Many ransomware families rely on well known encryption libraries but DeadLock diverges from this trend. By building a time seeded encryption routine, the group avoids reuse of keys and complicates the creation of universal decryptors. The design hints at an actor with significant development capability, one capable of refining its malware with each new campaign.

Telemetry showing the use of AnyDesk and enabled RDP channels confirms a dual purpose approach. They use stealth during the initial phase, then pivot to remote management tools to navigate the system manually. This is the same pattern seen in high level intrusions where attackers prefer hands on access to expand control, deploy payloads, and assess network value in real time.

From a defensive perspective, BYOVD remains one of the most challenging attack paths. Many organizations do not maintain strict driver loading policies, leaving outdated kernel modules capable of being exploited by malware. Even with Microsoft’s blocklist, enforcement is often inconsistent. DeadLock takes advantage of this disconnect, proving that kernel exploitation is no longer limited to state sponsored actors.

Looking forward, this group may evolve into a more mature ransomware operation with broader infrastructure, but their current posture suggests a preference for selective, high impact intrusions. Their communication strategy and lack of public leak platforms point toward a quieter ecosystem where victims are less likely to report incidents. This model is profitable and difficult to track, which may inspire similar operators to adopt the same formula.

Fact Checker Results

The DeadLock campaign uses a real CVE associated with a Baidu Antivirus driver.
The described BYOVD exploitation method aligns with Cisco Talos analysis.
DeadLock’s use of Session messenger for negotiation is confirmed by multiple sources. ✅

Prediction

DeadLock is likely to evolve toward more modular attacks, adding layered privilege escalation tools and alternate persistence channels. ⚡
The use of vulnerable drivers may expand as attackers discover more abandoned kernel modules across legacy systems. 🔍
Ransomware operations may increasingly adopt private negotiation channels instead of public leak sites, changing the visibility of extortion campaigns. 📊

🕵️‍📝✔️Let’s dive deep and fact‑check.

References:

Reported By: cyberpress.org
Extra Source Hub (Possible Sources for article):
https://www.linkedin.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2
Bing

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon