Unveiling BYOVD Threats: Malware's Use and Abuse of Kernel Drivers
Andrea Monzani, Antonio Parata, Andrea Oliveri, Simone Aonzo, Davide Balzarotti, Andrea Lanzi · 2026
the OS kernel [1].However, vulnerable drivers are routinely patched and replaced with new, more secure versions.This is what makes a BYOVD scenario so dangerous and effective against modern Windows systems.In these attacks, malicious software brings along its own copy of a vulnerable third-party driver and loads it into the operating systemeffectively reintroducing into the system an old vulnerability it already knows how to exploit.In recent years, BYOVD attacks have been linked to statesponsored cyber espionage campaigns and sophisticated ransomware operations [2], in which attackers use this technique to disable detection and ensure the success of their malicious activities [3].Moreover, the fact that these attacks rely on trusted and signed drivers means that BYOVD attacks can often remain undetected for extended periods of time, allowing attackers to conduct prolonged, stealthy campaigns.While BYOVD is becoming increasingly popular among malware authors, defense techniques are lagging behind.For instance, modern Endpoint Detection and Response (EDR) systems, although effective at monitoring user-mode activity, are often blind to actions that take place in the kernel.Even existing dynamic analysis systems and malware analysis sandboxes fall short in detecting these threats.For instance, when a malware sample loads and abuses the Zemana anti-malware driver to terminate Windows Defender, public sandboxes on VirusTotal detect only the driver load event, but fail to capture how it is used once loaded into the system.This limitation stems from a fundamental lack of visibility into internal kernel-level communications.While a significant body of research has been focused on detecting malicious activity within the kernel [4], [5], [6], [7]especially in the context of rootkits and driver-based threatsexisting approaches remain limited in their ability to reconstruct the kernel drivers' control flows.Hardware-assisted runtime monitoring approaches [8] primarily focused on kernel memory integrity, but lacked insight into behavioral context or user-mode interactions.HookScout [9], instead, introduced a combination of static and dynamic analysis to detect kernel rootkits via anomalous control flow, yet struggled with obfuscation and dynamic resolution-techniques now common in modern BYOVD attacks.Other dynamic systems have applied taint tracking and control-flow tracing to detect kernel interface Abstract-Bring Your Own Vulnerable Driver (BYOVD) attacks abuse legitimate, digitally signed Windows drivers that contain hidden flaws, allowing adversaries to slip into kernel space, disable security controls, and sustain stealthy campaigns ranging from ransomware to state-sponsored espionage.Because most public sandboxes inspect only user-mode activity, this kernel-level abuse typically flies under the radar.In this work, we first introduce the first dynamic taxonomy of BYOVD behavior.Synthesized from manual investigation of real-world incidents and fine-grained kernel-trace analysis, it maps every attack to sequential stages and enumerates the key APIs abused at each step.Then, we propose a virtualization-based sandbox that follows every step of a driver's execution path, from the originating user-mode request down to the lowest-level kernel instructions, without requiring driver re-signing or host mod-ifications.Finally, the sandbox automatically annotates every observed action with its corresponding taxonomy, producing a stage-by-stage report that highlights where and how a sample exhibits suspicious behavior.Tested against the current landscape of BYOVD techniques, we analyzed 8,779 malware samples that load 773 distinct signed drivers.It flagged suspicious behavior in 48 drivers, and subsequent manual verification led to the responsible disclosure of seven previously unknown vulnerable drivers to Microsoft, their vendors, and public threat-intelligence platforms.Our results demonstrate that deep, transparent tracing of kernel control flow can expose BYOVD abuse that eludes traditional analysis pipelines, enriching the community's knowledge of driver exploitation and enabling proactive hardening of Windows defenses.