Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors reynolds

Description

Reynolds is a ransomware family first identified in early 2026, notable for embedding BYOVD (Bring Your Own Vulnerable Driver) defense evasion by exploiting CVE-2025-68947 to terminate security software before encrypting files, initially attributed to Black Basta and considered attractive to RaaS affiliates. Known victims: 1 1 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Reynolds is a medium-sized criminal threat actor group primarily involved in ransomware activities for financial gain. They were first identified on November 13, 2025, and are notable for their use of Bring Your Own Vulnerable Driver (BYOVD) defense evasion techniques to terminate security software before encrypting files. Initially linked to Black Basta, Reynolds has attracted attention from Ransomware as a Service (RaaS) affiliates due to its modular and adaptable approach.

Goals & Targeting

Reynolds' primary objectives are financial gain through ransomware attacks. The group targets sectors where high-value data is concentrated, such as healthcare, education, and corporate enterprises, with a focus on mid-sized to large organizations that may lack robust incident response plans. Geographically, Reynolds appears to target regions with weaker cybersecurity frameworks and higher payout potential, though specific targeting patterns remain limited due to its early stage of operation.

Enhanced Description

Reynolds is a relatively new ransomware family that emerged in early 2026. It gained notoriety for its innovative use of the BYOVD defense evasion technique, which involves exploiting known vulnerabilities like CVE-2025-68947 to disable security software before encrypting victim files. This approach makes detection and mitigation more challenging for organizations. Reynolds' association with Black Basta suggests a possible link to established cybercriminal networks, but the group's broader origins remain unclear. The ransomware's modular design and RaaS-friendly model have made it attractive to affiliate groups, enabling its rapid proliferation in the cybercrime ecosystem. Despite its relatively recent emergence, Reynolds has demonstrated operational sophistication through its technical capabilities and targeting strategies.

Key Capabilities

  • Exploitation of CVE-2025-68947 for defense evasion
  • BYOVD technique to terminate security software
  • Ransomware deployment with extortion notes in multiple languages
  • Lateral movement within networks using tools like PSExecute
  • Encrypted command-and-control (C2) communication channels

MITRE ATT&CK Tactics

Reconnaissance
Discovery
Initial Access
Execution
Defense Evasion

ATT&CK Techniques

T1203.001 - Exploit Public-Exposure Vulnerability
T1584.001 - Defense Evasion via Driver
T1566.001 - Phishing手法
T1805 - Data Destruction/Encryption
T1059.003 - Command-line Instrument.exe

Software / Tooling

ExploitKit
PSExecute
Cobalt Strike
Custom Ransomware

Campaigns & Victims

Reynolds' campaigns are characterized by their use of RaaS affiliates, rapid deployment, and focus on high-value targets. The group's short operational history limits known campaign patterns, but initial sightings suggest a preference for North American and European targets in the financial and healthcare sectors. Reynolds has demonstrated an ability to adapt quickly, incorporating feedback from affiliates to improve its attack toolkit.

IOC Patterns

  • Spear-phishing emails with malicious Office documents
  • Exploitation of CVE-2025-68947
  • Ransomware payload delivery via encrypted files
  • Lateral movement using PSExecute and other tools
  • C2 communication over HTTP/HTTPS channels

Recommended Actions

  • Patch systems to mitigate known vulnerabilities like CVE-2025-68947
  • Monitor for suspicious processes and lateral movement indicators
  • Implement email filtering to detect phishing attempts
  • Conduct regular backups of critical data and isolate backup assets
  • Educate employees on ransomware awareness and safe email practices

Suggested Tags

Ransomware
Criminal
BYOVD
Financial-Gain

Confidence Assessment

Low to medium confidence. Reynolds' limited operational history and lack of detailed campaign data make it challenging to attribute attacks definitively. The absence of specific targets or infrastructure further complicates threat intelligence gathering, leaving gaps in understanding their full capabilities and long-term goals.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

1

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Criminal
BYOVD
Financial-Gain

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Nov 13, 2025
Last Seen
Nov 13, 2025
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.