logo

EDR Killers Broaden Ransomware Tactics, ESET Warns

ID: a615d759-fb2f-5fd1-bed4-4b264a9357f0

STIX ID: report--a615d759-fb2f-5fd1-bed4-4b264a9357f0

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-04-13

Date Updated: 2026-07-21

Author: Mayura Kathir

...
...

ESET telemetry-backed research shows ransomware affiliates are increasingly using nearly 90 distinct EDR-killer tools — including BYOVD vulnerable-driver exploits, legitimate anti-rootkit utilities repurposed to kill defenses, and emerging driverless techniques — to blind or cripple endpoint security prior to deploying ransomware. The report highlights commercialization of these tools, evidence of rapid adoption (and potential AI-assisted development), misleading attribution from reused drivers, and urges a prevention-first, multi-layered defensive approach combining BYOVD hardening, anti-rootkit monitoring, and telemetry-driven hunting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.