
A cybercriminal group linked to RansomHub has developed a new tool called EDRKillShifter, which is designed to neutralize endpoint detection and response (EDR) systems. This tool exploits vulnerable drivers to escalate privileges and execute payloads stealthily. Researchers from Sophos observed the deployment of this utility by an undetermined criminal group targeting organizations with ransomware attacks. The introduction of EDRKillShifter, a BYOVD Binary, marks an escalation in tactics by ransomware gangs, as noted by Sophos X-Ops.
Sophos X-Ops: Ransomware gangs escalating tactics, going to 'chilling' lengths https://t.co/IGdjVbvI56 https://t.co/8Ny5iKW4GP
RansomHub Rolls Out Brand-New, EDR-Killing BYOVD Binary: https://t.co/O7TtUORj7l by darkreading #infosec #cybersecurity #technology #news
A group linked to RansomHub operation employs EDR-killing tool EDRKillShifter https://t.co/58vARcGlft