logo

Ransomware Actors Expand EDR Killer Tactics Beyond Vulnerable Drivers

ID: 9b4d5c27-464a-5c56-9682-58bfa57eb973

STIX ID: report--9b4d5c27-464a-5c56-9682-58bfa57eb973

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-03-20

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

The report outlines a growing trend where ransomware affiliates deploy EDR killers—via vulnerable drivers (BYOVD), scripts, misuse of anti-rootkit software, or driverless techniques—to reliably disable endpoint security before encryption. ESET telemetry and incident investigations found ~90 active EDR killers (including commercial offerings like AbyssKiller and CardSpaceKiller) used across many ransomware groups (e.g., Akira, Medusa, LockBit), highlighting a mature underground market and emphasizing the need for layered detection, driver blocklists, privilege restriction, network segmentation, and robust endpoint telemetry.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.