RansomHub Rolls Out Brand-New, EDR-Killing BYOVD Binary
ID: c1d03a8d-783d-58d3-9920-f118ce4fe030
STIX ID: report--c1d03a8d-783d-58d3-9920-f118ce4fe030
Feed Name: Dark Reading
Date Published: 2024-08-16
Date Updated: 2026-05-05
Author: Tara Seals, Managing Editor, News, Dark Reading
RansomHub has deployed a new loader called EDRKillShifter that decrypts and runs an embedded payload which drops and exploits vulnerable signed drivers to escalate privileges and unhook EDR protections (a bring-your-own-driver/BYOVD technique). Sophos X-Ops links the tool to a broader rise in EDR-killer malware (e.g., AuKill, Terminator) and recommends enforcing Windows security role hygiene and separation of user/admin privileges to mitigate these attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
