logo

Packer-as-a-Service Shanya Hides Ransomware, Kills EDR

ID: 28d242eb-53b2-5520-9bec-ca03e9619acd

STIX ID: report--28d242eb-53b2-5520-9bec-ca03e9619acd

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2025-12-09

Date Updated: 2026-04-21

Author: Alexander Culafi

...
...

Sophos research describes 'Shanya', a packer-as-a-service used to obfuscate ransomware and deploy a clean legitimate driver plus a malicious unsigned kernel driver to kill EDR products; the tool has been observed in use by multiple ransomware groups worldwide in 2025, and Sophos published IOCs and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.