Reynolds is a ransomware family first identified in early 2026, notable for embedding BYOVD (Bring Your Own Vulnerable Driver) defense evasion by exploiting CVE-2025-68947 to terminate security software before encrypting files, initially attributed to Black Basta and considered attractive to RaaS affiliates. Known victims: 1 1 ransom note(s) on file
Objectives
Executive Summary
Reynolds is a medium-sized criminal threat actor group primarily involved in ransomware activities for financial gain. They were first identified on November 13, 2025, and are notable for their use of Bring Your Own Vulnerable Driver (BYOVD) defense evasion techniques to terminate security software before encrypting files. Initially linked to Black Basta, Reynolds has attracted attention from Ransomware as a Service (RaaS) affiliates due to its modular and adaptable approach.
Goals & Targeting
Reynolds' primary objectives are financial gain through ransomware attacks. The group targets sectors where high-value data is concentrated, such as healthcare, education, and corporate enterprises, with a focus on mid-sized to large organizations that may lack robust incident response plans. Geographically, Reynolds appears to target regions with weaker cybersecurity frameworks and higher payout potential, though specific targeting patterns remain limited due to its early stage of operation.
Enhanced Description
Reynolds is a relatively new ransomware family that emerged in early 2026. It gained notoriety for its innovative use of the BYOVD defense evasion technique, which involves exploiting known vulnerabilities like CVE-2025-68947 to disable security software before encrypting victim files. This approach makes detection and mitigation more challenging for organizations. Reynolds' association with Black Basta suggests a possible link to established cybercriminal networks, but the group's broader origins remain unclear. The ransomware's modular design and RaaS-friendly model have made it attractive to affiliate groups, enabling its rapid proliferation in the cybercrime ecosystem. Despite its relatively recent emergence, Reynolds has demonstrated operational sophistication through its technical capabilities and targeting strategies.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Reynolds' campaigns are characterized by their use of RaaS affiliates, rapid deployment, and focus on high-value targets. The group's short operational history limits known campaign patterns, but initial sightings suggest a preference for North American and European targets in the financial and healthcare sectors. Reynolds has demonstrated an ability to adapt quickly, incorporating feedback from affiliates to improve its attack toolkit.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Low to medium confidence. Reynolds' limited operational history and lack of detailed campaign data make it challenging to attribute attacks definitively. The absence of specific targets or infrastructure further complicates threat intelligence gathering, leaving gaps in understanding their full capabilities and long-term goals.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
1
IOCs
0
Observed Data
0
Tactics