logo

Shanya EDR Killer Leveraged by Ransomware Groups to Clear the Way for Ransomware Infection

ID: 2dedeb2e-ceab-51b5-a2db-ec3448cc28b5

STIX ID: report--2dedeb2e-ceab-51b5-a2db-ec3448cc28b5

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2025-12-08

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

The report describes the emergence of 'Shanya', a sophisticated packer-as-a-service and EDR-killer that uses DLL side-loading and vulnerable third-party drivers (BYOVD) to escalate to kernel privileges, disable endpoint protections, and enable ransomware deployments; researchers link it to multiple ransomware families and active campaigns across regions such as the UAE and Tunisia.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.