Back to News
Market Impact: 0.12

CyberDagger LLC and Titan Code Solutions Contribute Qihoo 360 BYOVD Primitive to LOLDrivers Catalog

Cybersecurity & Data PrivacyTechnology & InnovationLegal & Litigation
CyberDagger LLC and Titan Code Solutions Contribute Qihoo 360 BYOVD Primitive to LOLDrivers Catalog

CyberDagger LLC contributed a BYOVD primitive to the LOLDrivers catalog after reverse engineering Qihoo 360 Total Security’s 360hvm64.sys driver. The finding shows a standalone load allows a single IOCTL call (0x0022240c) to disable Intel VT-x or AMD-V across all logical CPUs due to an authentication gate failing open. The update is tied to MITRE ATT&CK T1562.001 and includes YARA rules, SOC behavioral indicators, and WDAC blocklist guidance, indicating elevated defense risk for environments running the affected driver stack.

Analysis

This is a security-hygiene event, not a semiconductor demand event. The market’s first-pass mistake will be to read the presence of AMD/INTC in the technical chain as chip-specific risk; in reality the economic beneficiary is the endpoint-control stack: EDR, application control, WDAC/policy-management tooling, and vendors that monetize kernel-driver visibility. If this primitive gets reused in ransomware or APT playbooks, the incremental spend lands with defenders rather than with CPU vendors.

For AMD and INTC, the direct P&L impact is likely de minimis over days to months. The only meaningful second-order angle is perception: enterprises that rely on virtualization-heavy security products may reassess driver signing, blocklists, and hardware-rooted controls, which can slightly favor platforms with tighter management and telemetry integration. That is a small tailwind for Microsoft’s security ecosystem and large EDR names, but it should not move hardware multiples unless a broader campaign ties this technique to real outages.

The catalyst path is binary: if SOCs and cloud providers rapidly update blocklists and WDAC policies, the issue fades in 1-3 weeks; if we see follow-on exploitation in widely deployed malware, the story extends 1-3 months and could drive incremental security budget. The contrarian view is that this is probably overread as a vendor-specific stain; the real risk is operational, not strategic, and the headline may create a better entry point to buy cyber exposure on weakness than to short semis. Falsifier: no evidence of in-the-wild abuse, no driver revocation activity, and no change in enterprise security guidance by the next patch cycle.

More News