logo

RansomHub Rolls Out Brand-New, EDR-Killing BYOVD Binary

ID: c1d03a8d-783d-58d3-9920-f118ce4fe030

STIX ID: report--c1d03a8d-783d-58d3-9920-f118ce4fe030

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-08-16

Date Updated: 2026-05-05

Author: Tara Seals, Managing Editor, News, Dark Reading

...
...

RansomHub has deployed a new loader called EDRKillShifter that decrypts and runs an embedded payload which drops and exploits vulnerable signed drivers to escalate privileges and unhook EDR protections (a bring-your-own-driver/BYOVD technique). Sophos X-Ops links the tool to a broader rise in EDR-killer malware (e.g., AuKill, Terminator) and recommends enforcing Windows security role hygiene and separation of user/admin privileges to mitigate these attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.