logo

Hackers Exploit SonicWall SSLVPN Credentials to Deploy EDR Killer and Bypass Security

ID: 541c4d64-59fe-5d10-ad70-27efaca43aaa

STIX ID: report--541c4d64-59fe-5d10-ad70-27efaca43aaa

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-02-05

Date Updated: 2026-04-21

Author: Guru Baran

...
...

Threat actors leveraged compromised SonicWall SSLVPN credentials to gain network access and deployed a sophisticated BYOVD-based “EDR killer” that loads a revoked EnCase kernel driver (dropped as C:\ProgramData\OEM\Firmware\OemHwUpd.sys) to terminate and persistently disable endpoint security processes; the report includes IOCs (two source IPs and two SHA-256 hashes), detailed TTPs (custom wordlist encoding, timestomping, IOCTL usage, kill-loop), and persistence mechanisms.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.