logo

Bring Your Own Installer EDR Bypass Observed in Ransomware Operation

ID: da7a62bf-71cf-5766-bafa-337a42d519f6

STIX ID: report--da7a62bf-71cf-5766-bafa-337a42d519f6

Feed Name: Halcyon Blog

Threat Score
75/100

Date Published: 2025-06-17

Date Updated: 2026-04-28

...
...

**Bring Your Own Installer (BYOI) EDR bypass used in ransomware attacks:** Researchers observed attackers with administrative access forcibly terminate the vendor installer (msiexec.exe) during legitimate agent upgrades—after protections are shut down but before the new agent is deployed—to disable endpoint defenses and deploy ransomware; mitigation includes enabling an "Online Authorization" approval feature which was disabled by default in existing deployments but enabled by default for new installs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.