critical Code Vulnerability

Qilin + Warlock Ransomware — BYOVD Killing 300+ EDR Products

Severitycritical
Statusopen
DateApril 6, 2026
AffectsNearly every EDR vendor — 300+ products targeted
Sourcethehackernews.com

Details

Qilin deploys malicious msimg32.dll that terminates 300+ EDR drivers from nearly every security vendor. Warlock uses legitimate NSecKrnl.sys driver for kernel-level EDR killing, plus TightVNC, VS Code tunneling, and Cloudflare tunnels for C2. Reported by Cisco Talos and Trend Micro.