Akira Ransomware Hijacks Intel CPU Tool to Disable Microsoft Defender in BYOVD Attacks
The Akira ransomware group is exploiting a legitimate Intel CPU tuning driver (rwdrv.sys) to disable Microsoft Defender in a sophisticated Bring Your Own Vulnerable Driver (BYOVD) attack. Security researchers observed this evasion tactic paired with SonicWall VPN targeting and trojanized software installers, underscoring critical supply chain risks.