Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

RA World – Toshiba Bluetooth Stack Driver (toshdpdb.exe) BYOVD Load

Raworld Defense Evasion Sentinel
MITRE ATT&CK
Exploitation for Stealth
Data Source
DeviceFileEvents
Date Added
2026-07-23
Last Updated
2026-07-23
Source
ransomware.live group_tools dataset (raworld)
What This Detects
RA World loads the Toshiba Bluetooth stack driver (toshdpdb.exe) as a BYOVD vector – an uncommon driver choice for EDR evasion distinct from the more commonly abused GIGABYTE/Zemana drivers seen in other families.
Query
DeviceFileEvents
| where Timestamp > ago(1d)
| where FileName =~ "toshdpdb.exe" or (FileName endswith ".sys" and FolderPath has "toshiba")
| project Timestamp, DeviceName, FileName, FolderPath, InitiatingProcessFileName, InitiatingProcessAccountName

Hunting queries are starting points for threat hunting & detection engineering — validate table/column names against your own workspace schema and tune thresholds before turning any of these into a production alert rule.