logo

Ransomware gang deploys new malware to kill security software

ID: 2f361d0a-2553-51d2-a00a-35481dd584a4

STIX ID: report--2f361d0a-2553-51d2-a00a-35481dd584a4

Feed Name: DataBreaches.Net

Threat Score
72/100

Date Published: 2024-08-15

Date Updated: 2026-04-19

Author: Dissent

...
...

RansomHub ransomware operators are using a new Bring Your Own Vulnerable Driver (BYOVD) malware, named EDRKillShifter by Sophos, to deploy a legitimate but vulnerable driver that disables EDR, elevates privileges, and enables full system control; observed during a May 2024 ransomware investigation, this technique is increasingly popular among both financially motivated gangs and state-backed groups.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.