Ransomware gang deploys new malware to kill security software
ID: 791c760c-06c7-5f26-9b67-4f6eed753213
STIX ID: report--791c760c-06c7-5f26-9b67-4f6eed753213
Feed Name: Bleeping Computer
Sophos researchers identified EDRKillShifter, a loader used by RansomHub and possibly other actors that deploys legitimate but vulnerable drivers (e.g., RentDrv2, ThreatFireMonitor) in BYOVD attacks to escalate privileges and terminate EDR processes so ransomware can run; researchers found multiple samples, associated proof-of-concept exploits on GitHub, evidence of attempted use in a May incident, and recommend tamper protection, least-privilege separation, and prompt driver/system patching.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
