TA Phone Home: EDR Evasion Testing Reveals Extortion Actor's Toolkit
ID: 652ab021-70d4-5d08-9cbd-1c73cc189048
STIX ID: report--652ab021-70d4-5d08-9cbd-1c73cc189048
Feed Name: Palo Alto Networks Unit 42
Date Published: 2024-11-01
Date Updated: 2026-04-28
Author: Navin Thomas, Renzon Cruz and Cuong Dinh
Unit 42 investigated an extortion incident where a threat actor acquired access via Atera RMM and used a virtual machine to test an AV/EDR bypass tool (disabler.exe) that loads a vulnerable driver (BYOVD). The investigation yielded Cobalt Strike and Mimikatz artifacts, video demos and forum posts linking the tool to a seller called "KernelMode", numerous host and network IOCs, and evidence used to profile and likely identify an individual associated with the rogue VM.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
