Ransomware gangs turn to Shanya EXE packer to hide EDR killers
ID: c67d3aba-08a2-594b-a9a9-be4bc1b5fb1e
STIX ID: report--c67d3aba-08a2-594b-a9a9-be4bc1b5fb1e
Feed Name: Bleeping Computer
Sophos researchers describe Shanya, a packer-as-a-service adopted by multiple ransomware gangs (including Medusa, Qilin, Crytox, and Akira) to obfuscate payloads and evade EDR. Shanya decrypts and injects payloads in memory (overwriting a memory-mapped copy of shell32.dll), employs anti-analysis techniques that crash user-mode debuggers, and enables DLL side-loading to deploy an EDR-killing toolchain using a signed vulnerable driver (rwdrv.sys) for escalation and an unsigned driver (hlpdrv.sys) to disable security products; IoCs and telemetry show active exploitation across several countries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
