Packer-as-a-Service Shanya Hides Ransomware, Kills EDR
ID: 28d242eb-53b2-5520-9bec-ca03e9619acd
STIX ID: report--28d242eb-53b2-5520-9bec-ca03e9619acd
Feed Name: Dark Reading
Threat Score
Sophos research describes 'Shanya', a packer-as-a-service used to obfuscate ransomware and deploy a clean legitimate driver plus a malicious unsigned kernel driver to kill EDR products; the tool has been observed in use by multiple ransomware groups worldwide in 2025, and Sophos published IOCs and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
