logo

RansomHub ransomware abuses Kaspersky TDSSKiller to disable EDR software

ID: 57f02fbc-83dd-5a5e-949a-295909cd927e

STIX ID: report--57f02fbc-83dd-5a5e-949a-295909cd927e

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-09-10

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

RansomHub has been observed abusing the legitimate Kaspersky TDSSKiller utility to interact with kernel-level services and disable EDR (e.g., Malwarebytes MBAMService) before deploying the LaZagne credential-harvesting tool to extract application credentials and enable lateral movement; executions were run from temporary directories with GUID-like filenames and used the '-dcsvc' flag to stop/delete services. The report highlights detection and mitigation guidance: enable EDR tamper protection, monitor for TDSSKiller execution and the '-dcsvc' parameter, and flag LaZagne activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.