Ransomware Gangs Expand Use of EDR Killers Beyond Vulnerable Drivers, ESET Warns
ID: 4e33bb05-a7a6-523f-9ef4-6e478477e2c0
STIX ID: report--4e33bb05-a7a6-523f-9ef4-6e478477e2c0
Feed Name: cybersecurityNews.com
ESET Research documents a rapidly expanding ecosystem of "EDR killers"—techniques and tools attackers use to disable endpoint detection and response before deploying ransomware—tracking almost 90 families (54 abusing vulnerable drivers across 35 drivers) and noting the rise of driverless methods, script-based approaches, legitimate anti-rootkit misuse, and commercialized "EDR killer as a service" offerings; this diversification, driven by affiliates, closed developer groups, and PoC reuse, complicates attribution and means defenders should prioritize behavioral detection of security tampering over tracking individual vulnerable drivers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
