Ransomware Actors Expand EDR Killer Tactics Beyond Vulnerable Drivers
ID: 9b4d5c27-464a-5c56-9682-58bfa57eb973
STIX ID: report--9b4d5c27-464a-5c56-9682-58bfa57eb973
Feed Name: cybersecurityNews.com
The report outlines a growing trend where ransomware affiliates deploy EDR killers—via vulnerable drivers (BYOVD), scripts, misuse of anti-rootkit software, or driverless techniques—to reliably disable endpoint security before encryption. ESET telemetry and incident investigations found ~90 active EDR killers (including commercial offerings like AbyssKiller and CardSpaceKiller) used across many ransomware groups (e.g., Akira, Medusa, LockBit), highlighting a mature underground market and emphasizing the need for layered detection, driver blocklists, privilege restriction, network segmentation, and robust endpoint telemetry.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
