RansomHub’s EDR-Killer Shows Up in Medusa, BianLian and Play Attacks
ID: 49562aae-f7d0-57f6-b0d8-5eb806c6855e
STIX ID: report--49562aae-f7d0-57f6-b0d8-5eb806c6855e
Feed Name: Halcyon Blog
A recent analysis reveals that RansomHub affiliates and other ransomware groups (Medusa, BianLian, Play) are deploying EDRKillShifter, a tool that uses Bring Your Own Vulnerable Driver (BYOVD) techniques to disable EDR and other security solutions, enabling ransomware encryption; cross-group reuse suggests collaboration or shared tooling, with actors QuadSwitcher and CosmicBeetle implicated. The report urges updating vulnerable drivers, enforcing installation controls and least-privilege, and deploying detections oriented to BYOVD/EDR-killer behaviors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
