Reynolds Ransomware — Ransomware Profile
Reynolds is a ransomware group first identified in February 2026, notable for embedding a Bring Your Own Vulnerable Driver (BYOVD) defense evasion component directly within its ransomware payload — rather than deploying a separate EDR killer as a prior stage. The payload drops the NsecSoft NSecKrnl kernel-mode driver (CVE-2025-68947) to terminate processes belonging to CrowdStrike Falcon, Palo Alto Cortex XDR, Sophos, Symantec Endpoint Protection, and Avast before initiating encryption. Reynolds was initially misattributed to Black Basta by Broadcom due to tactical similarities; further analysis by the Symantec and Carbon Black Threat Hunter Team confirmed it as a distinct new family. Observed intrusions feature extended dwell time via a side-loaded loader deployed weeks before the ransomware, followed by GotoHTTP deployment post-encryption for persistent access.
IntelFusions coverage (1)
Tools & malware
- GotoHTTP remote_access
- NSecKrnl.sys (NsecSoft NSecKrnl Driver) vulnerable_driver
- Reynolds Ransomware Payload ransomware
Vendor research
Read the full analysis on IntelFusions