logo

Ransomware gangs turn to Shanya EXE packer to hide EDR killers

ID: c67d3aba-08a2-594b-a9a9-be4bc1b5fb1e

STIX ID: report--c67d3aba-08a2-594b-a9a9-be4bc1b5fb1e

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2025-12-09

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Sophos researchers describe Shanya, a packer-as-a-service adopted by multiple ransomware gangs (including Medusa, Qilin, Crytox, and Akira) to obfuscate payloads and evade EDR. Shanya decrypts and injects payloads in memory (overwriting a memory-mapped copy of shell32.dll), employs anti-analysis techniques that crash user-mode debuggers, and enables DLL side-loading to deploy an EDR-killing toolchain using a signed vulnerable driver (rwdrv.sys) for escalation and an unsigned driver (hlpdrv.sys) to disable security products; IoCs and telemetry show active exploitation across several countries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.