Ransomware gang deploys new malware to kill security software
ID: 2f361d0a-2553-51d2-a00a-35481dd584a4
STIX ID: report--2f361d0a-2553-51d2-a00a-35481dd584a4
Feed Name: DataBreaches.Net
Threat Score
RansomHub ransomware operators are using a new Bring Your Own Vulnerable Driver (BYOVD) malware, named EDRKillShifter by Sophos, to deploy a legitimate but vulnerable driver that disables EDR, elevates privileges, and enables full system control; observed during a May 2024 ransomware investigation, this technique is increasingly popular among both financially motivated gangs and state-backed groups.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
