Ransomware Actors Exploit EDR Killers Beyond Vulnerable Drivers
Key Takeaways Ransomware groups are increasingly using sophisticated EDR killers beyond vulnerable drivers to disable security tools before deploying their payloads. Attackers are shifting their...
Key Takeaways
- Ransomware groups are increasingly using sophisticated EDR killers beyond vulnerable drivers to disable security tools before deploying their payloads.
- Attackers are shifting their technical efforts from making encryptors undetectable to outright destroying endpoint security defenses for a reliable attack window.
- A burgeoning commercial market now exists for EDR killer tools, which are bought, sold, and adapted to target a wide array of security products.
- The techniques include script-based tools, misuse of legitimate software, and fully driverless methods, often employing advanced obfuscation and anti-analysis features.
Ransomware operators are dramatically evolving their strategies to bypass endpoint detection and response (EDR) systems, moving beyond the long-standing practice of exploiting vulnerable drivers. This development points to a more advanced methodology aimed at neutralizing security defenses, according to recent research.
Table Of Content
For years, the “Bring Your Own Vulnerable Driver” (BYOVD) technique was the primary method threat actors used to disable security software before initiating their file-encrypting attacks. However, the landscape has become considerably more complex. Today, ransomware groups are deploying script-based utilities, misusing legitimate anti-rootkit software, and employing entirely driverless approaches to incapacitate security products before encryption commences.
This strategic shift underscores a crucial operational goal for ransomware affiliates: to secure a brief, dependable window during which their encryptors can run unhindered. Rather than expending significant effort on making encryptors invisible to security software—a task that is both difficult and time-consuming—attackers now prioritize the direct neutralization of security protection.
Consequently, EDR killers—tools specifically engineered to disable endpoint detection and response software—have become a critical component of nearly every contemporary ransomware assault. Research by ESET, based on telemetry data and real-world incident investigations, confirms that this trend is accelerating across both prominent and smaller ransomware collectives.
Analysts at WeLiveSecurity identified and monitored nearly 90 distinct EDR killers actively used in the wild, spanning almost every ransomware organization currently in operation. Of these, 54 are BYOVD-based tools that exploit 35 different vulnerable drivers, while 7 are script-based, and 15 leverage legitimate anti-rootkit or freely available software. The research highlights that the EDR killer ecosystem has matured into a structured, commercially driven market where these tools are acquired, traded, and customized to target numerous security vendors.
The implications of this shift are severe. Organizations now face attacks where their security tools are rendered inoperable even before the ransomware payload executes. Groups such as Akira, Medusa, Qilin, RansomHouse, and DragonForce have all been observed utilizing commercial EDR killers procured from underground marketplaces.
One commercially available tool, AbyssKiller, which combines the ABYSSWORKER rootkit with a HeartCrypt-packed loader, has emerged as one of the most frequently detected commercial EDR killers in active use. Another, CardSpaceKiller, is consistently seen in attacks by Akira, Medusa, and MedusaLocker, often obfuscated using the VX Crypt packer-as-a-service.
Detection Evasion: The Core of Modern Ransomware Sophistication
Unlike encryptors, which are solely focused on file encryption, EDR killers have become the primary method for defense evasion in ransomware operations. Threat actors are concentrating their technical expertise on these evasion tools rather than on the encryptors themselves, as directly disabling security software is often simpler and more reliable than attempting to make a payload undetectable. This deliberate division of labor has fostered the creation of powerful and accessible tools, even for attackers with limited technical proficiency.
A common tactic involves separating the EDR killer tool from the vulnerable driver it exploits, delivering them independently. The affiliate first manually installs the driver, confirming its successful loading, before executing the EDR killer. Commercial tools are frequently packaged using services like VX Crypt and HeartCrypt, which incorporate structure-level obfuscation, anti-virtual machine behaviors, and continuous repacking to thwart static detection. Code protectors such as VMProtect and Themida are also routinely employed.
Some tools go a step further by storing encrypted drivers or shellcode in separate files on disk, effectively keeping crucial components out of reach from defenders. SmilingKiller, for instance, observed in LockBit and Dire Wolf intrusions, employs control-flow flattening to complicate code analysis. CardSpaceKiller utilizes call-by-hash resolution and string obfuscation, while EDRKillShifter, developed by the now-defunct RansomHub group, password-protects critical sections of its code. The Warlock gang is known to deploy dozens of EDR killers per intrusion until one succeeds, with recent samples exhibiting patterns consistent with AI-assisted code generation.
What You Should Do
- Implement Robust Driver Blocking: While not sufficient on its own, maintaining an updated blocklist for known vulnerable drivers is a crucial first step. Actively monitor for suspicious driver installation events.
- Adopt Layered Detection Strategies: Employ a multi-layered security approach, ideally through a managed detection and response (MDR) provider or a dedicated internal Security Operations Center (SOC) team, to adapt to evolving attacker tactics.
- Restrict High-Privilege Access: Minimize the window of opportunity for attackers by strictly controlling high-privilege access across your network.
- Enforce Network Segmentation: Segment your network to limit lateral movement and contain potential breaches, reducing the impact if an EDR killer successfully bypasses a single endpoint.
- Maintain Strong Endpoint Telemetry: Ensure your endpoints continuously collect and transmit comprehensive telemetry data. This is critical for retaining visibility and forensic capabilities even if an initial layer of protection is compromised.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.