12.4 C
Canberra
Saturday, August 8, 2026

EDR killers defined: Past the drivers


In recent times, EDR killers have turn into one of the generally seen instruments in fashionable ransomware intrusions: an attacker acquires excessive privileges, deploys such a instrument to disrupt safety, and solely then launches the encryptor. Apart from the dominating Carry Your Personal Weak Driver (BYOVD) method, we additionally see attackers often abusing professional anti-rootkit utilities or utilizing driverless approaches to dam the communication of endpoint detection and response (EDR) software program or droop it in place. These instruments should not simply plentiful, but in addition behave predictably and constantly, which is exactly why associates attain for them.

On this blogpost, we current our view of EDR killers, grounded in ESET telemetry and incident investigations. The analysis relies on the evaluation and monitoring of just about 90 EDR killers actively used within the wild. Our focus goes past the susceptible drivers that dominate most discussions: we doc how associates choose, adapt, and function EDR killers throughout actual intrusions, and what which means for attribution and protection.

We clarify why driver-centric evaluation usually misleads group attribution, present concrete circumstances of driver reuse and switching throughout unrelated codebases, and spotlight the expansion of driverless disruption alongside commercialized, hardened kits. The result’s a transparent, evidence-based image of how EDR killers perform as a predictable stage in fashionable ransomware operations.

Key factors of this blogpost:

  • EDR killers are a elementary a part of fashionable ransomware intrusions; associates desire a brief, dependable window to run encryptors moderately than always modifying payloads.
  • Associates, not operators, choose the EDR killers; bigger affiliate swimming pools result in higher tooling variety.
  • The identical driver seems in unrelated instruments, and the identical instrument can migrate between drivers. Consequently, driver-based attribution to teams is commonly deceptive.
  • Packer as a service and “EDR killer as a product” enhance availability, muddy attribution, and add protection complexity.
  • EDR killers implement protection evasion methods, whereas encryptors focus purely on encryption.
  • We strongly suspect that AI assisted with the event of some EDR killers, and we offer a concrete instance with the Warlock gang.
  • Whereas BYOVD dominates, customized scripts, anti-rootkits, and driverless EDR killers are utilized as properly.

The EDR killer panorama

ESET researchers focus past the susceptible drivers so usually abused by these instruments. As we are going to display, drawing any connections solely primarily based on the misused drivers is inadequate and might result in incorrect assumptions.

The panorama this analysis unveils is huge, starting from infinite forking of proofs of idea (PoCs) to advanced skilled implementations. Specializing in business EDR killers (marketed on the darkish internet) permits us to achieve a greater understanding of their buyer base and spot in any other case hidden affiliations. In-house developed EDR killers provide insights into the internal workings of closed teams. Moreover, vibe coding is making issues much more difficult. We offer a technical overview of EDR killers, together with susceptible drivers, within the The expertise behind EDR killers part.

On the time of writing, our perception into the EDR killer panorama relies on the next:

  • We detect a complete of just about 90 EDR killers actively used within the wild by mainly any ransomware gang, large or small:

      54 of those are BYOVD-based, abusing a complete of 35 susceptible drivers,

    ○  7 of those are script-based, and

    ○  15 of those are anti-rootkits or different freely obtainable software program.

  • For twenty-four of the BYOVD-based EDR killers, we’re not conscious of a publicly obtainable PoC they’re primarily based on; we assess that their builders carried out these instruments from scratch and had been impressed solely by the motive force exploitation code.

All through this blogpost, we check with entities forming the ransomware-as-a-service mannequin as follows:

  • Operators, who develop the ransomware payload, handle decryption keys, preserve the devoted leak website, usually negotiate the ransom fee with victims, and provide different tooling and companies for a month-to-month payment or a proportion from the ransom fee (sometimes 5–20%).
  • Associates, who hire ransomware companies from operators, deploy encryptors to victims’ networks, and exfiltrate information from victims’ machines.

Why are EDR killers so well-liked?

To efficiently encrypt information, ransomware encryptors must evade detection. These days, a variety of mature evasion methods is obtainable, starting from packing and code virtualization to classy injection. Nonetheless, we hardly ever see any of those carried out in encryptors. As an alternative, ransomware attackers go for EDR killers to disrupt safety options proper earlier than encryptor deployment. This totally different method naturally raises the query: why not moderately make investments into making encryptors undetected?

Reliability and operational simplicity for encryptor builders

Ransomware gangs, particularly these with ransomware-as-a-service (RaaS) packages, often produce new builds of their encryptors, and guaranteeing that every new construct is reliably undetected will be time-consuming. Extra importantly, encryptors are inherently very noisy (as they inherently want to switch a lot of information in a brief interval); making such malware undetected is moderately difficult. EDR killers present a cleaner various. As an alternative of burying detection-evading logic inside each encryptor replace, attackers merely depend on an exterior instrument to disrupt or disable safety controls instantly earlier than execution, conserving encryptors easy, steady, and simple to rebuild.

Low value, excessive energy

As proven all through this blogpost, EDR killers are extraordinarily accessible. Not all intruders or associates have the talent set to develop their very own protection evasion methods. However due to massive collections of public PoCs, EDR killers have primarily turn into “plug-and-play”.

On the identical time, EDR killers usually depend on professional but susceptible drivers, making protection considerably harder with out risking disruption of legacy or enterprise software program. The result’s a category of instruments that provides kernel-level influence with minimal improvement effort, making these instruments disproportionately highly effective given their simplicity.

Predictability and repeatability throughout intrusions

Packing or injecting code could assist an implant slip previous detection, nevertheless it doesn’t make sure the long-term stability of the ransomware payload in the course of the ultimate part of the intrusion. As a result of layered safety offered by safety merchandise, packed encryptors should still be detected in reminiscence or at different levels of execution. EDR killers, alternatively, present a predictable and repeatable step within the assault chain, giving attackers a extra deterministic workflow. Moreover, EDR killers goal to disrupt the safety answer as a complete, successfully eliminating all safety layers.

The expertise behind EDR killers

Scripts

The best EDR killers don’t depend on susceptible drivers or different superior methods. As an alternative, they abuse built-in administrative instruments and instructions reminiscent of taskkill, internet cease, or sc delete to tamper with safety product processes and companies. These crude approaches nonetheless seem sometimes however at the moment are largely related to low-skill ransomware menace actors and commodity malware.

Barely extra subtle variants mix scripting with Home windows Protected Mode. Since Protected Mode hundreds solely a minimal subset of the working system, and safety options sometimes aren’t included, malware has a better probability of disabling safety. On the identical time, such exercise may be very noisy, because it requires a reboot, which is dangerous and unreliable in unknown environments. Subsequently, it’s seen solely hardly ever within the wild.

Grey zone: Anti-rootkits

Years in the past, earlier than Microsoft enforced kernel-mode driver signing, rootkits flourished within the cybercrime ecosystem, hiding malicious exercise by manipulating kernel buildings. Their prevalence led to the event of specialised anti-rootkit instruments designed to detect and take away them. As a result of rootkits function in kernel mode, such instruments naturally require excessive privileges and their very own drivers to find, enumerate, and neutralize the rootkits.

Right now, ransomware associates often abuse these identical anti-rootkit instruments: to not take away rootkits, however to cripple safety options. Many anti-rootkits provide a user-friendly GUI that enables customers (together with attackers with little technical functionality) to terminate protected processes or companies. In different phrases, professional remediation instruments have turn into handy EDR killers when misused. Such instruments embrace GMER (see Determine 1), HRSword, and PC Hunter.

Figure_01_GMER
Determine 1. The GUI of GMER, a preferred anti-rootkit answer

Rootkits

Though rootkits are largely uncommon in fashionable cybercrime, notable exceptions nonetheless floor. One instance from final 12 months is ABYSSWORKER, a kernel-mode rootkit that drew consideration after its creators managed to signal it utilizing certificates stolen from Chinese language corporations. These certificates had additionally been used to signal different malware and are subsequently not particular to ABYSSWORKER. For the reason that stolen certificates belong to a trusted certificates chain, such a driver remains to be allowed to run within the kernel. And, to make issues extra difficult, even certificates revocation shouldn’t be a bulletproof choice, as lately demonstrated by Huntress.

Weak drivers

The BYOVD method has turn into the hallmark of recent EDR killers: dominant, dependable, and broadly used. In a typical state of affairs, an attacker drops a professional however susceptible driver onto the sufferer machine, installs the motive force, after which runs malware that abuses the motive force’s vulnerability. The purpose is to terminate protected processes or disable callbacks that safety merchandise depend on.

Though there are millions of professional susceptible drivers, solely a relatively small subset is actively exploited in ransomware incidents. Nonetheless, the provision of public PoCs means that there’s successfully no restrict on the variety of menace actors that may undertake or adapt exploits for these vulnerabilities. Some attackers reuse present codebases with minimal or no modifications, others change no logic however reimplement them of their most well-liked programming language, and a few even develop solely new EDR killers (conserving solely a small portion of the unique code accountable for driver exploitation) that they both use on their very own or provide as a service.

Driverless EDR killers

Lastly, a smaller however rising class of EDR killers achieves its objectives with out touching the kernel in any respect. As an alternative of terminating EDR processes, these instruments intervene with different important options. Examples embrace instruments like EDRSilencer, which blocks communication between an endpoint and its safety backend, and EDR-Freeze, which causes EDR processes to “dangle” or turn into unresponsive. These driverless methods are well-liked as a result of their unconventional method makes detection and mitigation tougher, and they’re publicly obtainable. Certainly, ESET researchers have seen fast adoption of those instruments in a matter of days by ransomware menace actors.

Who develops EDR killers?

In 2025, ESET researchers printed an evaluation of EDRKillShifter, an EDR killer developed by RansomHub operators and provided on to their associates. On the time of writing, we’re not conscious of every other RaaS packages whose operators present their very own proprietary EDR killers. This makes the now-defunct RansomHub a notable exception within the ransomware panorama.

As an alternative, most menace actors fall into one of many following classes:

  • non-RaaS gangs growing their very own EDR killers,
  • attackers forking and barely modifying public proof-of-concept code, or
  • attackers buying an EDR killer from underground marketplaces.

Let’s break these conditions down in additional element.

Closed teams

Non-RaaS gangs normally function as totally closed ecosystems: no associates, no preliminary entry brokers, and no exterior companions. These teams preserve tight management over their intrusion workflows and sometimes depend on a repeatable, internally constant set of TTPs. Given this degree of operational self-discipline, growing their very own EDR killers turns into a pure extension of their toolset.

ESET researchers highlighted an early instance of this in-house improvement mannequin in 2024 with the Embargo gang. On the time, Embargo relied on two EDR killers:

  • a customized Protected Mode script, leveraging the method already described earlier, and
  • MS4Killer, a instrument impressed by the publicly obtainable s4killer PoC.

Though MS4Killer was primarily based on an obtainable PoC, its builders made vital modifications: they added parallelism, modified the code circulate, and encrypted strings and the embedded driver. For the reason that publication of that analysis, Embargo has shifted to one more public PoC, evil‑mhyprot‑cli, this time with minimal code modifications.

A second, newer, instance is the DeadLock gang. DeadLock maintains a low profile by avoiding having a devoted leak website and conducting all negotiations via Session, a well-liked various to the extra frequent Tox. ESET researchers have noticed DeadLock utilizing two EDR killers, DLKiller (additionally talked about as an unnamed loader by Cisco Talos) and Susanoo, and anti-rootkits reminiscent of GMER and PC Hunter. ESET researchers imagine with low confidence that DLKiller and the DeadLock encryptor are the work of the identical developer resulting from notable, however by itself inconclusive, code similarities. Apparently, Susanoo offers a loading display screen and a GUI, each offered in Determine 2, permitting for handbook interplay and anticipating the attacker to have interactive entry to the sufferer’s machine.

Figure_02_Susanoo
Determine 2. Susanoo EDR killer’s loading display screen (left) and GUI (proper)

Because the screenshot clearly demonstrates, Susanoo gives buttons to pre-load the checklist of monitored processes – a devoted one focusing on Sophos-related processes and a “TNT” one focusing on all processes identified to Susanoo.

The third and ultimate instance is Warlock. Though the Warlock leak website has been silent since November 6th, 2025, the group stays operational and retains increasing its technical arsenal. The gang is understood for its willingness to experiment: it tailored the VS Code abuse method for stealthy distant entry, beforehand documented in September 2024 and used by the Mustang Panda APT group, whereas additionally pioneering the malicious use of Velociraptor. Ever since, Warlock has constantly relied on these methods. Its method to encryptors mirrors this sample as properly – Warlock has employed a number of totally different encryptors over time, starting from customized ones to variants primarily based on Babyk or generated utilizing the leaked LockBit Black builder.

Given all that, Warlock’s experimentation with EDR killers is no surprise. For the reason that gang first appeared, it has routinely deployed a number of EDR killers per intrusion, generally even dozens throughout current operations, successfully brute-forcing its approach to a working answer. Warlock’s tooling is numerous not solely in amount but in addition in technical depth: the gang doesn’t restrict itself to a single susceptible driver and has abused at the very least 9 totally different drivers so far, together with some with none publicly obtainable PoC (at the very least to our data); a element that underscores the group’s technical proficiency and its capability to adapt offensive instruments past what is quickly publicly obtainable.

Modification of a PoC

That is by far the most typical method noticed in ransomware intrusions. Menace actors often take an present, well-tested PoC, and alter solely the noncritical elements earlier than deploying it in actual assaults. These modifications sometimes embrace:

  • eradicating or altering debugging messages,
  • including code obfuscation,
  • adjusting the checklist of focused safety merchandise, and
  • rewriting the instrument in a special programming language.

The essential level, nonetheless, is that the core exploitation logic, particularly the half that interacts with the susceptible driver, nearly by no means modifications. This logic is commonly so simple as calling the Home windows API DeviceIoControl with a “right” dwIoControlCode worth and the title of the method to terminate in lpInBuffer. Whereas renaming strings, restructuring the codebase, or reimplementing the instrument in one other language are operations that don’t require deep technical data, modifying the exploitation logic actually is and subsequently is usually averted.

Whereas there are numerous publicly obtainable PoCs for EDR killers, one repository stands out: BlackSnufkin’s BYOVD. Usually up to date, it comprises (on the time of writing) PoCs for exploiting 10 susceptible drivers, every carried out following the identical modular template. The implementation permits for simple modifications, extensions, and new driver assist. Moreover, the code is properly documented (see Determine 3), making this repository essentially the most often used one in ransomware exercise within the wild.

Figure_03_BlackSnufkin
Determine 3. BdApiUtil-Killer, certainly one of BlackSnufkin’s PoCs with an in depth utilization information

We detected certainly one of BlackSnufkin’s EDR killers, TfSysMon-Killer, deployed throughout a Monti ransomware assault in February 2025; the deployed variant was equivalent functionality-wise, however was reimplemented from Rust to C++, prone to align with different instruments of the menace actor. One other instance of language switching is dead-av, which its writer overtly describes as a Go rewrite of GhostDriver, one other PoC created by BlackSnufkin.

A extra in depth modification effort will be seen in SmilingKiller, an EDR killer lately noticed by ESET researchers throughout LockBit and Dire Wolf intrusions. Its developer was impressed by kill-floor, an EDR killer PoC that abuses Avast’s aswArPot.sys. Apart from modifying debug messages and including control-flow flattening obfuscation (see Determine 4), the writer additionally switched the abused driver to K7RKScan.sys, the identical driver abused by K7Terminator, one other of BlackSnufkin’s PoCs.

Figure_04_SmilingKiller_KillFloor
Determine 4. Code similarities between kill-floor (left, purple) and SmilingKiller (blue, proper), with particular similarities highlighted in pink

EDR killer as a service

Given the robust and rising demand for EDR-disruption instruments, it’s no shock {that a} parallel market for business EDR killers has emerged. The vary of choices is large: some ads present solely imprecise guarantees with no technical particulars, whereas others embrace in depth characteristic lists, utilization directions, and even video demonstrations. Beneath are three notable examples.

One such commercial, disclosed by Flare in October 2025, originated from a menace actor utilizing the moniker Бафомет. The menace actor marketed an EDR killer that ESET researchers later named DemoKiller. ESET telemetry confirms that DemoKiller has been utilized by associates of the Qilin, Akira, and Gents gangs, and we additionally noticed it deployed as soon as throughout a RansomHouse intrusion. The commercial is proven in Determine 5.

Figure_05_DemoKiller_ad
Determine 5. The commercial for DemoKiller (supply: Flare)

One other paid EDR killer revolves across the ABYSSWORKER rootkit, beforehand mentioned on this blogpost. When paired with its HeartCrypt-packed loader part, which ESET researchers named AbyssKiller, this EDR killer has turn into one of the generally noticed business ones within the wild. ESET researchers have seen AbyssKiller utilized by associates of the Medusa, DragonForce, and the now-disrupted BlackSuit gangs.

The ultimate noteworthy instance is an EDR killer that we name CardSpaceKiller. This instrument is constantly packed utilizing VX Crypt, a comparatively new packer as a service analyzed by Sophos in late 2025. VX Crypt shouldn’t be distinctive to this EDR killer; it has additionally been used to guard different malware households reminiscent of BumbleBee. In response to Sophos, CardSpaceKiller has appeared in intrusions involving Akira, Medusa, Qilin, and Crytox. ESET telemetry aligns with these findings and moreover reveals deployment throughout MedusaLocker incidents. Analyzing the unpacked payload, it’s instantly clear that this EDR killer comes from a business providing, the place the developer tries to deal with edge circumstances with a warning (see Determine 6).

Figure_06_CardSpaceKiller
Determine 6. A part of CardSpaceKiller’s code demonstrating the developer making an attempt to handle edge circumstances which will occur for purchasers

The character and value of such commercially marketed instruments fluctuate. Some declare to promote supply code, others solely particular person builds. The worth is commonly a matter of particular person negotiation; when disclosed publicly, the value has assorted from lots of to hundreds of US {dollars}.

EDR killers and AI

Whereas the set of abused susceptible drivers stays comparatively small, the variety of distinct user-mode elements which are a part of fashionable EDR killers within the wild is rising quickly. Given this surge in quantity and selection, it’s pure in 2026 to ask: is AI contributing to this proliferation?

Figuring out whether or not AI straight assisted in producing a particular codebase is commonly virtually unimaginable. There isn’t a definitive forensic marker that reliably distinguishes AI-generated code from human-written code, particularly when attackers post-process or obfuscate it. Nonetheless, ESET researchers assess that at the very least some lately noticed EDR killers exhibit traits strongly suggestive of AI-assisted technology.

A transparent instance seems in an EDR killer lately deployed by Warlock. The instrument comprises a piece of code that not solely prints an inventory of Potential fixes, a sample typical for AI-generated boilerplate, but in addition, as a substitute of exploiting a particular driver, implements a trial-and-error mechanism that cycles via a number of unrelated, generally abused machine names till it finds one which works. The corresponding code is proven in Determine 7.

Figure_07_AI
Determine 7. Seemingly AI-generated code of an EDR killer utilized by Warlock

Past the drivers

Absolutely understanding the EDR killer ecosystem requires trying far past susceptible drivers. Whereas driver exploitation stays a dominant pillar of many instruments, it’s only one a part of a wider panorama. Our analysis reveals that specializing in drivers alone obscures significant relationships between instruments, associates, and exercise clusters.

A key statement is the division of labor in RaaS ecosystems. Operators sometimes provide the encryptor and supporting infrastructure, however EDR killer choice is left to associates. Which means that the bigger the affiliate pool, the extra numerous the EDR killer tooling turns into. On the identical time, the constant reuse of particular instruments inside specific clusters may help determine new affiliations, strengthen infrastructure linkages, and reveal operator-affiliate relationships that might stay invisible if one appeared solely at encryptor households.

Driver reuse and switching

Public PoCs have made driver exploitation broadly accessible, however this has created a deceptive scenario: the identical susceptible driver is commonly reused throughout unrelated EDR killers, and the identical EDR killer can make the most of totally different drivers over time. Because of this, driver-based attribution alone is error-prone.

A transparent instance is the Baidu Antivirus driver BdApiUtil.sys, which seems in a number of unbiased tasks, together with:

  • dead-av,
  • BdApiUtil-Killer,
  • DLKiller,
  • HexKiller, certainly one of Warlock’s EDR killers, and
  • SevexKiller, a current EDR killer detected throughout Akira deployments.

The identical sample seems with the TfSysMon.sys driver (ThreatFire System Monitor). It’s abused by TfSysMon-Killer, Susanoo, and EDRKillShifter – three codebases with distinct implementations and improvement histories.

Driver switching is equally frequent. CardSpaceKiller, for instance, initially relied on HwRwDrv.sys, however later variants migrated to ThrottleStop.sys with minimal modifications to the remaining logic. The driving force is interchangeable; the exploitation layer stays largely the identical.

This illustrates the broader level: drivers are a commodity useful resource, and their presence alone offers little perception into menace actor sophistication or relationships.

Detection evasion

Attackers aren’t placing a lot effort into making their encryptors undetected. Relatively, all the subtle defense-evasion methods have shifted to the user-mode elements of EDR killers. This pattern is most seen in business EDR killers, which regularly incorporate mature anti-analysis and anti-detection capabilities. Notable recurring methods embrace:

  • Driver decoupling. The killer and the motive force are sometimes delivered individually. Associates manually set up the motive force first, verifying that it hundreds efficiently earlier than executing the precise EDR-killing part.
  • Use of business packers. Packers reminiscent of VX Crypt (as used with CardSpaceKiller) and HeartCrypt (as used with AbyssKiller) present structure-level obfuscation, anti‑VM habits, and steady repacking to evade static signatures. Common code virtualization protectors like VMProtect and Themida are additionally favored.
  • Encrypted embedded drivers. When a driver is bundled with an EDR killer, it’s often saved in encrypted type.
  • Exterior encrypted payloads. Some EDR killers retailer encrypted shellcode or auxiliary elements in separate information. This method successfully hides essential components of the killer from being simply accessible to defenders.
  • Code obfuscation. Frequent methods embrace control-flow flattening (SmilingKiller), call-by-hash decision (CardSpaceKiller), and string obfuscation
  • Password safety. EDRKillShifter is an ideal instance of utilizing this system. Defending an important a part of the EDR killer with a password creates detection challenges, but in addition offers analysis alternatives.

Defending in opposition to ransomware and EDR killers

Defending in opposition to ransomware requires a basically totally different mindset than defending in opposition to automated threats. Phishing emails, commodity malware, and exploit chains cease as soon as detected and neutralized by safety options; ransomware intrusions don’t. They’re interactive, human-driven operations, and intruders regularly adapt to detections, instrument failures, and environmental obstacles. Because of this, even when particular person steps are detected, they solely have defensive worth if defenders – whether or not an inside SOC staff, an MSSP, or an MDR supplier – reply appropriately, instantly, and with adequate decisiveness.

Most EDR killers depend on professional however susceptible drivers, which is why defenders usually instinctively deal with driver blocking. Blocking the motive force from loading is a vital step and does certainly neutralize the EDR killer, however solely on the final potential second. By the point an affiliate makes an attempt to put in the motive force, they sometimes have already got excessive privileges and are seconds away from launching the encryptor. If the EDR killer fails, they’ll merely strive one other instrument.

As a result of these drivers are professional, overly aggressive blocking dangers disrupting business-critical software program, complicating incident dealing with. Focused blocking additionally faces challenges. In February 2025, Verify Level confirmed that menace actors had been in a position to create over 2,500 samples of Truesight.sys, all of them remaining validly signed resulting from a weak spot within the signature validity checking course of. Truesight.sys can be certainly one of many examples of a weak spot in Microsoft’s driver signing coverage. A 12 months later, in February 2026, Huntress analyzed an intrusion the place EnPortv.sys was abused regardless of its certificates being expired and explicitly revoked.

For this reason a prevention-first technique is important. Blocking generally misused drivers from loading is an efficient and needed protection mechanism, nevertheless it shouldn’t be the one one. Learning EDR killers permits defenders to give you a multilayered technique that expands the horizons; the purpose is to cease the EDR killer earlier than execution. In any case, in the case of ransomware, the best protection technique is to have strategies in place to detect, comprise, and remediate the menace at each potential step.

Conclusion

EDR killers endure as a result of they’re low-cost, constant, and decoupled from the encryptor – an ideal match for each encryptor builders, who don’t must deal with making their encryptors undetectable, and associates, who possess an easy-to-use, highly effective utility to disrupt defenses previous to encryption.

Our analysis presents telemetry-backed insights into the EDR killer ecosystem that transfer previous the generally seen driver-centric method. We doc how associates, not operators, form tooling variety, and the way codebases routinely reuse and swap drivers. We define how the previous 12 months noticed more and more commercialized choices for EDR killers, and showcase how business EDR killers particularly can provide the protection evasion methods generally lacking in encryptors.

We emphasize that whereas stopping susceptible drivers from loading is a vital step within the line of protection, it might additionally result in potential enterprise disruptions, which is why one shouldn’t rely solely on that and goal to disrupt EDR killers earlier than they even get an opportunity to load the motive force. Moreover, we demonstrated that driverless approaches, whether or not script- or vulnerability-based, are a well-liked addition to any ransomware menace actor’s arsenal.

For any inquiries about our analysis printed on WeLiveSecurity, please contact us at threatintel@eset.com
ESET Analysis gives personal APT intelligence stories and information feeds. For any inquiries about this service, go to the ESET Menace Intelligence web page.

IoCs

A complete checklist of indicators of compromise (IoCs) and samples will be present in our GitHub repository.

Recordsdata

SHA-1 Filename Detection Description
54547180A99474B0DBA289D92C4A8F3EEA78B531
2Gk8.exe
Win32/Loader.Lycaon.Y.gen AbyssKiller EDR killer.
75F85CAEA52FE5A124FA77E2934ABD3161690ADD
smuot.sys
Win64/Rootkit.Agent.DX The ABYSSWORKER rootkit.
002573D80091F7F8167BCBDA3A402B85FA915F19
lasdjfioasdjfioer.exe
Win64/HackTool.EDRSilencer.C EDRSilencer EDR killer.
1E7567C0D525AD037FBBBAFB643BF40541994411
EDR-Freeze.exe
Win64/HackTool.EDRFreeze.A EDR-Freeze EDR killer.
65C2388B0AFB1D1F1860BB887456D8D6CD8B5645
Killer.exe
Win64/KillAV.DQ EDRKillShifter EDR killer.
A9F37104D2D89051F34E1486BC6EBFF44D147E67
EDRGay.exe
Win32/KillAV.NVJ DLKiller EDR killer.
083F604377D74C4377822EF35021E34AD7DACEEA
susanoo.exe
Win64/KillAV.CQ Susanoo EDR killer.
570161A420992280A8ECED253EDC800296B72D1C
vmtools.exe
Win32/KillAV.NVL HexKiller EDR killer.
BBE0E14BC7ECE8A7A1236D5A12E30476CFCEF110
Check.exe
WinGo/KillAV.M SevexKiller EDR killer.
31CE76931CA09D3918B34E3187703BC72E6D647E
TfSysMon-Killer.exe
Win64/KillAV.DP TfSysMon-Killer EDR killer.
B9820BF443C375577CEEF44B9491E3A569A1B9E8
deadav.exe
WinGo/KillAV.L dead-av EDR killer.
34270B07538B7357CF10D0D5BDA68F234B602F93
zcasdfhsdjfhoqewruoqwe.exe
Win64/KillAV.DP GhostDriver EDR killer.
09735640D6634B0303755A9FD3B2BC80F932126C
pip.exe
Win32/KillAV.NVQ SmilingKiller EDR killer.
85BC0A4F67522D6AC6BE64D763E65A2945EC5028
kill-floor.exe
Win64/KillAV.AV kill-floor EDR killer.
711C95FEAD2215E9AC59E32E6E3B0D71AD5C5AA5
demor.exe
Win64/Agent.GAJ DemoKiller EDR killer.
BC65ED919988C8E4B8F5A1CD371745456601700A
demo.exe
Win64/KillAV.DR DemoKiller EDR killer.
148C0CDE4F2EF807AEA77D7368F00F4C519F47EF
BdApiUtil64.sys
drivergay.sys
Gosling.sys
kihost.sys
Win64/VulnDriver.Baidu.D Baidu Antivirus BdApi susceptible driver.
468121E7D6952799F92940677268937C4C5F92ED
K7RKScan.sys
K7RKScan_1516.sys
wamsdk.sys
Win64/VulnDriver.K7Computing.A K7RKScan Kernel Module susceptible driver.
C881F43C7FE94A6F056A84DA8E9A32FE56D8DD9C
elliot.sys
kill.sys
TfSysMon.sys
WatchMgrs.sys
Win64/Riskware.PCInstruments.A ThreatFire System Monitor susceptible driver.
67D17CA90880B448D5C3B40F69CEC04D3649F170
1721894530.sys
rentdrv2.sys
Win64/VulnDriver.RentDrv.A Rentdrv2 susceptible driver.
F329AE0FDF1E198BEA6BA787E59CB73F90714002
information.sys
Win64/VulnDriver.AMD.E USB-C Energy Supply Firmware Replace Utility susceptible driver.
82ED942A52CDCF120A8919730E00BA37619661A3
NitrogenK.sys
rwdrv.sys
ThrottleBlood.sys
ThrottleStop.sys
Win64/VulnDriver.GPUZ.B ThrottleStop susceptible driver.
CE1B9909CEF820E5281618A7A0099A27A70643DC
hlpdrv.sys
Win64/Agent.GRL Customized rootkit utilized by CardSpaceKiller.
5D6B9E80E12BFC595D4D26F6AFB099B3CB471DD4
aswArPot.sys
kallmekris.sys
Win64/VulnDriver.Avast.A Avast anti-rootkit susceptible driver.
7310D6399683BA3EB2F695A2071E0E45891D743B
probmon.sys
Sysprox.sys
Win64/VulnDriver.ITMSystem.A ITM SYSTEM File Filter susceptible driver.
C85C9A09CD1CB1691DA0D96772391BE6DDBA3555
kl.sys
rspot.sys
Win64/VulnDriver.Rising.A Beijing Rising Community Safety susceptible driver.
6EE94F6BDC4C4ED0FFF621FEC36C70FF093659ED
msupdate.sys
thelper.sys
Win32/IP-guard.E OCular THelper susceptible driver.
BA14C43031411240A0836BEDF8C8692B54698E05
praxisbackup.exe
Win64/Agent.ECW MS4Killer EDR killer.
127B50C8185986A52AE66BF6E7E67A6FD787C4FC
model.dll
Win64/KillAV.CardSpaceKiller.C CardSpaceKiller EDR killer.
A3BDB419703A70157F2B7BD1DC2E4C9227DD9FE8
0th3r_av5.exe
Win64/KillAV.CardSpaceKiller.A CardSpaceKiller EDR killer.
4A57083122710D51F247367AFD813A740AC180A1
DrKiller_Cry_0x000E25C5DF65A3A.exe
Win64/Kryptik.FBC CardSpaceKiller EDR killer.
DB8BCB8693DDF715552F85B8E2628F060070F920
HwRwDrv.sys
MegaDrov.sys
Win64/VulnDriver.HwRwDrv.C CardSpaceKiller EDR killer.

MITRE ATT&CK methods

This desk was constructed utilizing model 18 of the MITRE ATT&CK framework.

Tactic ID Title Description
Execution T1059.003 Command and Scripting Interpreter: Home windows Command Shell Script-based EDR killers use taskkill, sc, internet cease, and comparable instructions to tamper with safety.
T1569.002 System Providers: Service Execution EDR killers execute susceptible drivers as companies.
Persistence T1543.003 Create or Modify System Course of: Home windows Service Some EDR killers could create companies to run throughout Protected Mode or at subsequent boot.
T1037.001 Boot or Logon Initialization Scripts: Logon Script (Home windows) EDR killers register scripts and companies to run early at boot to intervene with EDR loading.
Privilege Escalation T1068 Exploitation for Privilege Escalation BYOVD-based EDR killers exploit susceptible drivers to escalate kernel-level privileges.
Protection Evasion T1562.001 Impair Defenses: Disable or Modify Instruments EDR killers terminate or droop EDR/AV processes and companies to bypass detection.
T1562.009 Impair Defenses: Protected Mode Boot Script-based EDR killers reboot methods into Protected Mode to tamper with safety elements.
T1070.004 Indicator Removing: File Deletion EDR killers could try to delete EDR/AV information to disable protections.
T1562.006 Impair Defenses: Indicator Blocking Driverless EDR killers block telemetry and community communication (e.g., EDRSilencer).
T1027 Obfuscated Recordsdata or Data Industrial EDR killers particularly use obfuscation and encryption (e.g., CardSpaceKiller).
T1027.009 Obfuscated Recordsdata or Data: Embedded Payloads Some EDR killers embed the drivers straight into their user-mode elements, usually encrypted.
T1027.002 Obfuscated Recordsdata or Data: Software program Packing Industrial EDR killers depend on packers like HeartCrypt or VX Crypt, and likewise superior code protectors like Themida and VMProtect.
T1027.005 Obfuscated Recordsdata or Data: Indicator Removing from Instruments EDR killers like SmilingKiller use control-flow flattening and code obfuscation.
T1140 Deobfuscate/Decode Recordsdata or Data Some EDR killers retailer encrypted drivers and shellcode in devoted information on disk.
Influence T1490 Inhibit System Restoration Some EDR killers delete or rename security-related information, impacting restoration.
T1489 Service Cease EDR killers cease protected companies of safety merchandise and tamper with their performance.

Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

[td_block_social_counter facebook="tagdiv" twitter="tagdivofficial" youtube="tagdiv" style="style8 td-social-boxed td-social-font-icons" tdc_css="eyJhbGwiOnsibWFyZ2luLWJvdHRvbSI6IjM4IiwiZGlzcGxheSI6IiJ9LCJwb3J0cmFpdCI6eyJtYXJnaW4tYm90dG9tIjoiMzAiLCJkaXNwbGF5IjoiIn0sInBvcnRyYWl0X21heF93aWR0aCI6MTAxOCwicG9ydHJhaXRfbWluX3dpZHRoIjo3Njh9" custom_title="Stay Connected" block_template_id="td_block_template_8" f_header_font_family="712" f_header_font_transform="uppercase" f_header_font_weight="500" f_header_font_size="17" border_color="#dd3333"]
- Advertisement -spot_img

Latest Articles