logo

RansomHub-linked EDR-killing malware spotted in the wild

ID: 6baaa7f1-2e6d-52a7-b49f-7458a94868ed

STIX ID: report--6baaa7f1-2e6d-52a7-b49f-7458a94868ed

Feed Name: The Register (Security)

Threat Score
72/100

Date Published: 2024-08-19

Date Updated: 2026-04-26

Author: Brandon Vigliarolo

...
...

Infosec in brief: Sophos analysts identified EDRKillShifter, a Windows malware that leverages known vulnerable drivers to disable EDR and deploy RansomHub; SolarWinds Web Help Desk (CVE-2024-28986) is a critical Java deserialization RCE now believed to be exploited; thousands of NetSuite public sites may leak customer PII due to misconfiguration; recent ransomware/data-theft incidents impacted an Australian mining company and Kootenai Health (≈500k patient records); and ReliaQuest highlights five impactful malware families including infostealers and Rust-based threats.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.