EDR killer tool uses signed kernel driver from forensic software
ID: 704ec719-9f7d-5a7b-8ceb-f49f494877a8
STIX ID: report--704ec719-9f7d-5a7b-8ceb-f49f494877a8
Feed Name: Bleeping Computer
Huntress investigated an intrusion where attackers used compromised SonicWall VPN credentials (without MFA) to deploy a disguised EDR-killer that leverages an old, revoked EnCase kernel driver (EnPortv.sys) via a BYOVD technique to obtain kernel-level control, terminate 59 security-related processes, establish reboot-persistent OEM-style driver persistence, and perform aggressive internal reconnaissance; the activity is linked to suspected ransomware but was interrupted before the final payload was deployed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
