logo

EDR-Killers Increasingly Used to Bypass Security in Ransomware Operations

ID: 569663ea-b00f-5fff-949a-c63bb138eb5d

STIX ID: report--569663ea-b00f-5fff-949a-c63bb138eb5d

Feed Name: Halcyon Blog

Threat Score
78/100

Date Published: 2025-04-01

Date Updated: 2026-04-28

...
...

Ransomware groups are increasingly adopting specialized "EDR-killer" tools and techniques—including exploitation of vulnerable Windows drivers, rootkits, universal unhooking, and the misuse of legitimate monitoring software (e.g., HRSword)—to disable or evade endpoint detection and response (EDR) systems, enabling undetected data theft, lateral movement (NetSupport RAT, Smbexec), and more effective ransomware deployments; the report cites incidents involving RansomHub, GlobeImposter, and Phobos and stresses the critical need for early detection and blocking of these tools.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.