Hunting the Hunter: How Ransomware Gangs Turned Your AV Into the Weakest Link
There's a grim irony baked into the modern ransomware playbook. The software you installed specifically to keep attackers out has, in a growing number of documented cases, become the door they walk right through. Not around. Not past. Through.
This isn't a fringe theory circulating on obscure forums. It's a pattern that incident responders, kernel security researchers, and threat intelligence teams have been watching accelerate over the past several years — and it's one that mainstream AV vendors have been frustratingly slow to address publicly.
The Privileged Position Problem
To understand why antivirus software makes such an attractive target, you have to think about what it actually does at the system level. AV products don't just scan files sitting in a folder. They operate with some of the highest privilege levels available on a Windows or macOS machine. Kernel-mode drivers, real-time hooks into file system operations, deep integration with network stacks — this is the plumbing that makes AV work.
But that same privileged position is exactly what makes it so valuable to an attacker. If you can exploit a vulnerability in an AV kernel driver, you don't need to fight through User Account Control prompts or find a separate privilege escalation bug. You're already operating at ring-0 or near it. You've skipped several steps in the attack chain in one move.
Security researcher Will Dormann, who spent years at CERT/CC cataloging software vulnerabilities, has pointed out repeatedly that security products often carry a false halo effect — the assumption that because something is security software, it must be more secure than average. In practice, the codebase complexity required to do what AV does creates a substantial attack surface that doesn't always get the scrutiny it deserves.
The Update Mechanism: A Trusted Pipe With a Leaky Valve
Kernel drivers aren't the only angle. AV update mechanisms have become a high-value target in their own right, particularly in the context of supply-chain attacks.
Think about how your AV software stays current. It's pulling definition files and, periodically, binary updates from vendor servers — often over authenticated but not always perfectly hardened channels. It's doing this automatically, with elevated privileges, because that's what you need it to do. Now think about what happens if an attacker can tamper with that pipeline.
In 2020, the SolarWinds compromise demonstrated at industrial scale how a trusted software update mechanism could be weaponized to deliver malicious code to thousands of organizations simultaneously. AV vendors aren't immune to the same class of attack. Several smaller-scale incidents — some disclosed, many quietly handled — have involved adversaries attempting to poison update infrastructure or perform man-in-the-middle attacks against AV update channels on enterprise networks.
The Lapsus$ group, before its members faced legal consequences, reportedly discussed internally the value of targeting security tooling specifically because of the implicit trust organizations extend to it. When your EDR or AV solution pushes an update, most security teams aren't inspecting that traffic the way they'd inspect an executable downloaded from a random website.
BYOVD: Bring Your Own Vulnerable Driver
One of the more technically sophisticated techniques gaining traction is what researchers call BYOVD — Bring Your Own Vulnerable Driver. Here, attackers don't need to find a zero-day in your specific AV product. Instead, they drop a legitimate but known-vulnerable signed driver onto the system, exploit that driver to gain kernel access, and then use that foothold to disable or manipulate AV software from below.
This technique has been documented in attacks attributed to groups including BlackByte ransomware operators and the threat actor known as Scattered Spider. The MSI driver vulnerability exploited by BlackByte in 2022 is a textbook example: a legitimate, signed driver with a known flaw became the skeleton key that unlocked kernel-level control and let the attackers effectively blind endpoint security tools before dropping their ransomware.
What makes BYOVD particularly nasty is that it sidesteps code-signing requirements. The driver is signed. It's legitimate. Your AV may not flag it. And by the time the ransomware payload actually executes, the security tooling meant to catch it has already been neutralized.
Why Vendor Security Audits Keep Falling Short
So why aren't AV vendors catching up faster? A few reasons, none of them flattering.
First, there's the audit lag problem. Third-party security audits of AV products are less common and less rigorous than the marketing around these products might suggest. Vendors have historically been reluctant to open their kernel-mode code to external review — both for competitive reasons and because the complexity of that code makes audits expensive and time-consuming.
Second, the vulnerability disclosure ecosystem around AV products is messier than it should be. Researchers who find flaws in AV software sometimes face legal pushback when attempting responsible disclosure. Others find that vendor bug bounty programs either don't cover kernel components or pay out at rates that don't reflect the actual severity of what's been found.
Third, there's a marketing incentive problem. AV vendors sell protection. Publicly acknowledging that their product has a kernel-level vulnerability that ransomware operators are actively exploiting is not a great look. The result is that patches sometimes ship quietly, advisories are vague, and the broader security community — including the IT admins actually deploying these products — doesn't get a clear picture of the risk.
What This Means for Your Threat Model
None of this means you should ditch endpoint protection. That would be trading a complicated risk for a simpler, worse one. But it does mean that the "install AV and you're covered" mental model is dangerously outdated.
A few things worth considering if you're responsible for security at any scale:
Treat your security tooling as part of your attack surface. Monitor AV processes, driver loads, and update activity the same way you'd monitor any other privileged software. Anomalous behavior in your security stack deserves the same scrutiny as anomalous behavior anywhere else.
Know what drivers your AV product installs. Tools like DriverView or the Windows Driver Kit can help you inventory what's running at the kernel level. Cross-reference against known vulnerable driver databases — the LOLDrivers project maintains a useful public list.
Push vendors for transparency. Ask your AV vendor directly about their kernel-mode security audit cadence, their bug bounty scope, and their process for communicating driver vulnerabilities. If they can't give you a straight answer, that tells you something.
Layer your defenses with mutual distrust. No single security tool should have unchecked trust from the rest of your stack. Network-level monitoring, behavior analytics, and endpoint isolation capabilities that operate independently of your primary AV can catch what happens when the AV itself is compromised.
The Uncomfortable Bottom Line
The security industry has spent decades telling users and enterprises to trust antivirus software as a foundational layer of defense. That trust was always somewhat conditional — no security tool is perfect — but it was generally reasonable. What's changed is that sophisticated threat actors have recognized and begun systematically exploiting the privileged position AV occupies on modern systems.
Your antivirus is still worth running. But it's no longer reasonable to think of it as a watcher that stands apart from the threat landscape. In some of the most damaging ransomware incidents of the past few years, it was the first thing that got hit. The hunter became the hunted, and the rest of the network paid the price.
Keep your eyes open. Even on the tools you trust most.