Threat actors associated with Qilin and Warlock
ransomware operations have been observed using the bring
your own vulnerable driver (BYOVD) technique to silence
security tools running on compromised hosts, according to findings
from Cisco Talos and Trend Micro. Qilin attacks analyzed by
Talos have been found to deploy a malicious DLL named
"msimg32.dll,"
Read more https://thehackernews.com/2026/04/qilin-and-warlock-ransomware-use.html

