Ransomware

Ransomware Groups Increasingly Adopting EDR Killer Tools

ESET uncovers a link between RansomHub, Play, Medusa, and BianLian ransomware gangs as more groups adopt tools to disable EDR software.

ESET uncovers a link between RansomHub, Play, Medusa, and BianLian ransomware gangs as more groups adopt tools to disable EDR software.

Tools designed to disable endpoint detection and response (EDR) solutions are making their way to the arsenal of more and more ransomware gangs, ESET concluded during an investigation into a link between several well-known groups.

Following the demise of the LockBit and BlackCat ransomware groups in 2024, new threat actors rose to fame, including RansomHub, a ransomware-as-a-service (RaaS) organization that emerged in February 2024.

As ransomware affiliates migrated from different groups to it, such as the BlackCat affiliate allegedly behind the Change Healthcare hack, RansomHub became and remained the dominating threat on the landscape.

In May 2024, the group added to its arsenal EDRKillShifter, a custom EDR killer tool targeting numerous security solutions that relies on a password to protect the shellcode acting as a middle layer during its execution.

EDR killers are executed on a victim’s network to blind, corrupt, or terminate any security solution running on the local endpoints. While simple scripts can be used, more sophisticated tools deploy vulnerable drivers they then abuse to perform the malicious activity.

RansomHub made EDRKillShifter available to its affiliates through the RaaS panel they had access to, but ESET observed it being used in attacks involving other ransomware variants, including Play, Medusa, and BianLian.

Advertisement. Scroll to continue reading.

Because BianLian and Play are rather closed ransomware operations, their access to EDRKillShifter suggests that they might be collaborating with RansomHub, repurposing the RaaS’s tools in their attacks.

“We believe with high confidence that all these attacks were performed by the same threat actor, working as an affiliate of the four ransomware gangs,” ESET notes, referring to the threat actor as QuadSwitcher.

Other ransomware affiliates too were seen using EDRKillShifter, ESET says, adding that this is not the only tool that threat actors have been employing to disable security software. In fact, it says, there has been “an increase in the variety of EDR killers used by ransomware affiliates”.

The increased use of EDR killers is seen as a reaction to security solutions being more effective at detecting file-encrypting malware. The encryptors, ESET notes, rarely received major updates, to avoid the risk of introducing flaws.

The cybersecurity firm also notes that, while there are over 1,700 vulnerable drivers that EDR killer solutions could use, only a handful of them are abused, as there is tested code targeting them and threat actors do not have to write new code from scratch.

Aside from RansomHub, only one other RaaS operator has been observed adding an EDR killer to its offering, namely Embargo, which only has 14 victims listed on its leak site. Dubbed MS4Killer, its tool is based on public proof-of-concept (PoC) code.

Related: Medusa Ransomware Uses Malicious Driver to Disable Security Tools

Related: New Ransomware Group Claims Attack on US Telecom Firm WideOpenWest

Related: Albabat Ransomware Expands Targets, Abuses GitHub

Related Content

Cybercrime

Maksim Silnikau was the creator and administrator of the ransomware group and involved in Angler EK’s distribution.

Data Breaches

An extortion group stole personal, financial, and medical information from the hospital’s network.

Data Breaches

The bank holding company was hacked in June, but the investigation into the incident continues.

Data Breaches

The physical security firm says its alarm monitoring and system functionality have not been affected.

Ransomware

The INC Ransomware gang has been targeting vulnerable SMA1000 appliances for root access and lateral movement.

Data Breaches

Hackers were detected on Analog Devices systems in June, and an investigation found that they stole files.

Data Breaches

Ernst & Young previously confirmed that personal and financial information was stolen from a third-party management platform.

Ransomware

The critical unsafe deserialization flaw allows attackers to execute arbitrary code remotely, without authentication.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version