logo

New ‘BlackSanta’ EDR killer spotted targeting HR departments

ID: 436de6cf-38d8-538d-a950-2972cddcd968

STIX ID: report--436de6cf-38d8-538d-a950-2972cddcd968

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-03-10

Date Updated: 2026-07-17

Author: Bill Toulas

...
...

A Russian-speaking threat actor ran a year-long spear-phishing campaign targeting HR departments that delivered a sophisticated EDR-killer called BlackSanta. The attack chain used malicious ISO files (LNK launching PowerShell), steganography, DLL sideloading, process hollowing, and brought in kernel-capable drivers (RogueKiller, IObitUnlocker) to terminate security processes, weaken Defender settings, and exfiltrate sensitive data while avoiding detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.