Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

RansomHub – BadRentdrv2/ThreatFire Driver BYOVD Load

Ransomhub Defense Evasion Sentinel
MITRE ATT&CK
Exploitation for Stealth
Data Source
DeviceFileEvents
Date Added
2026-07-23
Last Updated
2026-07-23
Source
ransomware.live group_tools dataset (ransomhub)
What This Detects
Separately from its RMM-tool abuse, RansomHub loads the BadRentdrv2 and ThreatFire System Monitor vulnerable drivers to kill EDR at the kernel level — a distinct BYOVD signature from its C2/persistence tradecraft.
Query
DeviceFileEvents
| where Timestamp > ago(1d)
| where FileName has_any ("rentdrv2","badrentdrv","threatfire") or FileName endswith ".sys" and FolderPath has_any ("temp","programdata")
| where FileName has_any ("rentdrv2","threatfire")
| project Timestamp, DeviceName, FileName, FolderPath, InitiatingProcessFileName, InitiatingProcessAccountName

Hunting queries are starting points for threat hunting & detection engineering — validate table/column names against your own workspace schema and tune thresholds before turning any of these into a production alert rule.