Cybersecurity Panic: EDRKillShifter Tool Targets Endpoint Detection Systems

Cybercrime group RansomHub has unleashed EDRKillShifter, a new tool designed to terminate endpoint detection and response (EDR) software, joining the ranks of other notorious programs. Sophos discovered the tool during a failed ransomware attack, highlighting the evolving tactics of cybercriminals.

Hot Take:

Just when you thought it was safe to go back in the cyber water, RansomHub and its merry band of digital miscreants have unleashed EDRKillShifter, a tool so sneaky it makes Houdini look like an amateur magician. If your EDR software starts acting like it’s on a permanent coffee break, you know who to blame.

Key Points:

  • RansomHub gang introduces EDRKillShifter, a new tool for disabling endpoint detection and response (EDR) software.
  • EDRKillShifter is a loader executable that uses a ‘bring your own vulnerable driver’ (BYOVD) method.
  • Microsoft links RansomHub to the notorious Scattered Spider e-crime syndicate.
  • The tool leverages vulnerable drivers to gain elevated privileges and disable EDR software.
  • Mitigation strategies include keeping systems updated and separating user and admin privileges.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here