Ransomware Operators Disable EDR, Backup, and Telemetry Before Encryption
Key Takeaways Ransomware groups are increasingly neutralizing security defenses, including EDR, backup systems, and Windows telemetry, *before* initiating encryption. This tactic aims to blind...
Key Takeaways
- Ransomware groups are increasingly neutralizing security defenses, including EDR, backup systems, and Windows telemetry, *before* initiating encryption.
- This tactic aims to blind defenders, prevent early detection, and hinder recovery efforts.
- Ten prominent ransomware families, including Play, BlackByte, and LockBit, were identified as employing these defense-impairment techniques in 2026 tests.
- The disruption of security tools is typically a post-initial-access activity, allowing attackers to escalate privileges and move laterally undetected.
- Organizations must validate their security controls against these advanced tactics and ensure robust, isolated backup strategies.
Ransomware operators are systematically disabling critical security infrastructure, such as endpoint detection and response (EDR) tools, backup software, and Windows telemetry, prior to encrypting victim data. This pre-encryption sabotage aims to obscure their activities, prevent detection, and severely complicate a victim’s ability to respond or recover.
Table Of Content
A recent analysis, detailed in a report, analyzed data from 2026 to identify ten ransomware families that were least effectively prevented. These families consistently employed methods to impair defenses after initial network penetration, but before the final encryption stage.
Picus Security said in a report that the ransomware family “Play” exhibited the lowest prevention rate, at a mere 13%. BlackByte followed at 25%, with LockBit, BabLock, Magniber, FAUST, Sodinokibi (also known as REvil), Hive, BlackKingdom, and Maori also featuring prominently among the least-prevented threats. These findings underscore a critical shift in ransomware tactics, where attackers prioritize blinding their targets to maximize impact.
The Tradecraft of Defense Impairment
Analysts at Picus Security highlighted a consistent operational pattern: ransomware groups leverage defense-impairment techniques post-compromise. This isn’t an initial access vector, but rather a crucial step in the attack lifecycle. By disabling security tools and erasing forensic evidence, attackers can move through a compromised network, escalate privileges, and prepare for widespread encryption without triggering alerts. This creates a critical window where security teams are effectively operating in the dark.
The implications are severe. When endpoint visibility, event logging, and backup operations are simultaneously compromised, organizations lose their ability to detect an ongoing attack and their primary means of data recovery. This strategic neutralization of defenses has become a standard phase in contemporary ransomware attacks, as previously noted in reports on ransomware actors expanding EDR killer tactics.
The report shared with Cyber Security News (CSN) highlighted that terminating or altering security tools was among the most prevalent behaviors observed. This includes the cessation of security, backup, and database services, the uninstallation of protection software, and the systematic clearing of Windows event logs that would otherwise provide crucial forensic trails.
Ransomware Operators Disable EDR
The BabLock ransomware exemplifies this tactic. It has been documented abusing legitimate vendor uninstallers to remove antivirus, EDR, backup, and database processes. Following this, it clears Security and System event logs. This sequence creates a critical, unmonitored window during which data encryption can proceed with minimal resistance and leave scant evidence for incident responders.
LockBit 5.0 employs a different, sophisticated method by manipulating Event Tracing for Windows (ETW), a vital telemetry mechanism. This variant modifies a core event-writing function to return without logging data, effectively depriving monitoring tools of essential system signals. This behavior aligns with previous observations of LockBit 5.0’s tactics, which include log clearing and advanced anti-analysis features.
Beyond disabling security tools, ransomware operators also employ advanced payload hiding and execution techniques. Sodinokibi, for instance, encrypts its code until runtime, while Magniber can execute its malicious code within other legitimate processes. Play ransomware uses deceptive file names and locations, such as PSexesvc.exe to mimic Sysinternals PsExec and ReadMe.txt for its ransom note, to blend in
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.