🔴 [LATEST] 313 TEAM TARGETS AL RAJHI BANK AND SAUDI CIVIL DEFENSE, SITES UNREACHABLE FROM DOZENS OF LOCATIONS    ◆    🔴 [LATEST] DDOS QATAR INVESTMENT AUTHORITY: 1 CRITICAL SOVEREIGN WEB PORTAL DOWN    ◆    🔴 [LATEST] RIPPERSEC TARGETS ISRAEL CART: 1 CRITICAL E-COMMERCE PLATFORM DISRUPTED    ◆    🔴 [LATEST] US NAVY DDOS ATTACK: 3 CRITICAL MILITARY PORTALS DISRUPTED    ◆    🔴 [LATEST] QATAR LIVING DDOS ATTACK: 1 CRITICAL EXPATRIATE PORTAL DISRUPTED

~/ › Threat Intelligence › article

Threat Intelligence

Earth Longzhi and the BYOVD Threat: Bypassing Windows Kernel Security in Southeast Asia

> By Haider | Aug 04, 2026 | 3 min read

⚠️ THREAT INTELLIGENCE ADVISORY:
The core foundation of modern operating system security is under direct assault. Earth Longzhi, an aggressive sub-group operating under the umbrella of the prolific China-nexus APT41, has resurfaced in 2026 with highly targeted campaigns across Southeast Asia. Their primary weapon is not a zero-day exploit, but a sophisticated architectural bypass known as BYOVD (Bring Your Own Vulnerable Driver), allowing them to systematically disable enterprise security software from deep within the Windows Kernel.

Earth Longzhi

Recent threat telemetry indicates that Earth Longzhi is heavily targeting the healthcare, government, and manufacturing sectors in Malaysia, the Philippines, Vietnam, and Taiwan. The group’s objective is long-term, stealthy corporate espionage and the exfiltration of sensitive regional data. To achieve this without triggering modern Endpoint Detection and Response (EDR) solutions, they have perfected the art of attacking the operating system’s most privileged ring.

> TABLE_OF_CONTENTS [toggle]

The Mechanics of a BYOVD Attack

Modern operating systems like Windows 11 heavily restrict what software can run at the Kernel level (Ring 0). To load a driver into the Kernel, the driver must possess a valid, cryptographic Digital Signature from a trusted authority (such as Microsoft or a major hardware vendor). This prevents malware from easily establishing deep system persistence or interfering with security software.

To bypass this, Earth Longzhi utilizes the BYOVD technique. The threat actors do not write their own malicious drivers; doing so would require stealing a digital certificate. Instead, they scour the internet for legitimate, commercially signed drivers that have known, unpatched vulnerabilities (such as outdated anti-cheat software, old graphics card drivers, or deprecated antivirus components).

When Earth Longzhi breaches a target network, they drop this legitimate-but vulnerable-driver onto the compromised endpoint. Because the driver’s digital signature is valid, the Windows OS allows it to load directly into the Kernel. Once loaded, the attackers exploit the known vulnerability within that driver to execute arbitrary code with maximum system privileges.

Blinding the Defenders

Once Earth Longzhi achieves Ring 0 execution via the vulnerable driver, their immediate objective is the systematic neutralization of the victim’s security stack. Operating from the Kernel, the attackers have higher privileges than the EDR or Antivirus software running in the user space (Ring 3).

They execute “Killer” scripts that forcefully terminate security processes, delete EDR telemetry logs, and block security agents from communicating with their cloud consoles. Because the security software is killed from the Kernel level, the EDR agent is unable to trigger a “tamper protection” alert; it is simply rendered permanently blind. With the defenses dismantled, Earth Longzhi freely deploys custom backdoors, credential dumpers, and lateral movement tools without any fear of detection.

Earth Longzhi Intelligence Verification

Tactic / Attribute Operational Details Threat Severity
Attack Vector BYOVD (Bring Your Own Vulnerable Driver) exploitation at Ring 0. Critical
Primary Objective Forceful termination and blinding of enterprise EDR/Antivirus software. Critical
Target Regions Southeast Asia (Malaysia, Philippines, Vietnam, Taiwan). High

Mitigating the BYOVD Threat

Defending against BYOVD attacks requires proactive system hardening, as reactive EDR solutions are explicitly the target of this technique. System administrators must implement Microsoft’s Vulnerable Driver Blocklist and ensure it is strictly enforced via Windows Defender Application Control (WDAC). This blocklist prevents the OS from loading drivers that have been identified as vulnerable, even if their cryptographic signatures are technically valid.

In addition, maintaining strict Least Privilege access is paramount; loading a driver into the Windows Kernel requires administrative rights. By denying local admin privileges to standard users, organizations can effectively sever the initial stage of the BYOVD attack chain.

For ongoing technical analysis of APT41, Earth Longzhi, and the evolution of Kernel-level exploits in Asia, continue following our Threat Intelligence reports.


> subscribe_to_intel

Get CyberAsia threat intelligence updates by email. Unsubscribe anytime. Privacy Policy.

Mitigation & Prevention Strategies

Exploitation of vulnerabilities in critical infrastructure and edge devices requires immediate remediation to prevent catastrophic disruption:

  • Patch Management: Apply vendor-supplied security patches or firmware updates immediately. For legacy systems, deploy virtual patching via network firewalls.
  • Isolate OT Networks: SCADA and OT environments must be strictly isolated from corporate IT networks (the Purdue Model) to prevent spillover attacks.
  • Continuous Monitoring: Deploy Endpoint Detection and Response (EDR) solutions and monitor network traffic for indicators of compromise (IoCs) associated with known exploits.

Disclaimer: The information presented in this threat intelligence report is for educational and cybersecurity research purposes only. CyberAsia reports on cyber incidents to help organizations understand and defend against emerging threats. We do not provide hacking instructions, host stolen data, or endorse illegal activities.

> INTELLIGENCE_NOTICE

The report above detailing Earth Longzhi and the BYOVD Threat: Bypassing Windows Kernel Security in Southeast Asia is part of the CyberAsia public archive. For organizations requiring Indicators of Compromise (IoCs), YARA signatures, and specialized malware containment guidelines for threat intelligence threats, please refer to our Secure Drop or contact the research desk.

> ABOUT_AUTHOR: Haider

Lead Cyber Threat Intelligence (CTI) Editor at CyberAsia, specializing in regional cybercrime syndicates, threat actor tracking, and dark web intelligence investigations.

> related_intel --suggest