logo

RansomHub’s EDR-Killer Shows Up in Medusa, BianLian and Play Attacks

ID: 49562aae-f7d0-57f6-b0d8-5eb806c6855e

STIX ID: report--49562aae-f7d0-57f6-b0d8-5eb806c6855e

Feed Name: Halcyon Blog

Threat Score
75/100

Date Published: 2025-03-27

Date Updated: 2026-04-28

...
...

A recent analysis reveals that RansomHub affiliates and other ransomware groups (Medusa, BianLian, Play) are deploying EDRKillShifter, a tool that uses Bring Your Own Vulnerable Driver (BYOVD) techniques to disable EDR and other security solutions, enabling ransomware encryption; cross-group reuse suggests collaboration or shared tooling, with actors QuadSwitcher and CosmicBeetle implicated. The report urges updating vulnerable drivers, enforcing installation controls and least-privilege, and deploying detections oriented to BYOVD/EDR-killer behaviors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.