RansomHub ransomware abuses Kaspersky TDSSKiller to disable EDR software
ID: 57f02fbc-83dd-5a5e-949a-295909cd927e
STIX ID: report--57f02fbc-83dd-5a5e-949a-295909cd927e
Feed Name: Bleeping Computer
RansomHub has been observed abusing the legitimate Kaspersky TDSSKiller utility to interact with kernel-level services and disable EDR (e.g., Malwarebytes MBAMService) before deploying the LaZagne credential-harvesting tool to extract application credentials and enable lateral movement; executions were run from temporary directories with GUID-like filenames and used the '-dcsvc' flag to stop/delete services. The report highlights detection and mitigation guidance: enable EDR tamper protection, monitor for TDSSKiller execution and the '-dcsvc' parameter, and flag LaZagne activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
