Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
CEVA Logistics Data Breach Exposes Valve Steam Hardware Buyers’ Information
August 10, 2026
Ransomware Operators Disable EDR, Backup, and Telemetry Before Encryption
August 10, 2026
AsyncRAT, Remcos, Xworm Among Week’s Top Malware Threats
August 10, 2026
Home/Threats/Ransomware Operators Disable EDR, Backup, and Telemetry Before Encryption
Threats

Ransomware Operators Disable EDR, Backup, and Telemetry Before Encryption

Key Takeaways Ransomware groups are increasingly neutralizing security defenses, including EDR, backup systems, and Windows telemetry, *before* initiating encryption. This tactic aims to blind...

David kimber
David kimber
August 10, 2026 3 Min Read
2 0

Key Takeaways

  • Ransomware groups are increasingly neutralizing security defenses, including EDR, backup systems, and Windows telemetry, *before* initiating encryption.
  • This tactic aims to blind defenders, prevent early detection, and hinder recovery efforts.
  • Ten prominent ransomware families, including Play, BlackByte, and LockBit, were identified as employing these defense-impairment techniques in 2026 tests.
  • The disruption of security tools is typically a post-initial-access activity, allowing attackers to escalate privileges and move laterally undetected.
  • Organizations must validate their security controls against these advanced tactics and ensure robust, isolated backup strategies.

Ransomware operators are systematically disabling critical security infrastructure, such as endpoint detection and response (EDR) tools, backup software, and Windows telemetry, prior to encrypting victim data. This pre-encryption sabotage aims to obscure their activities, prevent detection, and severely complicate a victim’s ability to respond or recover.

Table Of Content

  • Key Takeaways
  • The Tradecraft of Defense Impairment
  • Ransomware Operators Disable EDR

A recent analysis, detailed in a report, analyzed data from 2026 to identify ten ransomware families that were least effectively prevented. These families consistently employed methods to impair defenses after initial network penetration, but before the final encryption stage.

Picus Security said in a report that the ransomware family “Play” exhibited the lowest prevention rate, at a mere 13%. BlackByte followed at 25%, with LockBit, BabLock, Magniber, FAUST, Sodinokibi (also known as REvil), Hive, BlackKingdom, and Maori also featuring prominently among the least-prevented threats. These findings underscore a critical shift in ransomware tactics, where attackers prioritize blinding their targets to maximize impact.

The Tradecraft of Defense Impairment

Analysts at Picus Security highlighted a consistent operational pattern: ransomware groups leverage defense-impairment techniques post-compromise. This isn’t an initial access vector, but rather a crucial step in the attack lifecycle. By disabling security tools and erasing forensic evidence, attackers can move through a compromised network, escalate privileges, and prepare for widespread encryption without triggering alerts. This creates a critical window where security teams are effectively operating in the dark.

The implications are severe. When endpoint visibility, event logging, and backup operations are simultaneously compromised, organizations lose their ability to detect an ongoing attack and their primary means of data recovery. This strategic neutralization of defenses has become a standard phase in contemporary ransomware attacks, as previously noted in reports on ransomware actors expanding EDR killer tactics.

The report shared with Cyber Security News (CSN) highlighted that terminating or altering security tools was among the most prevalent behaviors observed. This includes the cessation of security, backup, and database services, the uninstallation of protection software, and the systematic clearing of Windows event logs that would otherwise provide crucial forensic trails.

Ransomware Operators Disable EDR

The BabLock ransomware exemplifies this tactic. It has been documented abusing legitimate vendor uninstallers to remove antivirus, EDR, backup, and database processes. Following this, it clears Security and System event logs. This sequence creates a critical, unmonitored window during which data encryption can proceed with minimal resistance and leave scant evidence for incident responders.

LockBit 5.0 employs a different, sophisticated method by manipulating Event Tracing for Windows (ETW), a vital telemetry mechanism. This variant modifies a core event-writing function to return without logging data, effectively depriving monitoring tools of essential system signals. This behavior aligns with previous observations of LockBit 5.0’s tactics, which include log clearing and advanced anti-analysis features.

Beyond disabling security tools, ransomware operators also employ advanced payload hiding and execution techniques. Sodinokibi, for instance, encrypts its code until runtime, while Magniber can execute its malicious code within other legitimate processes. Play ransomware uses deceptive file names and locations, such as PSexesvc.exe to mimic Sysinternals PsExec and ReadMe.txt for its ransom note, to blend in

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackransomwareSecurityThreat

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

AsyncRAT, Remcos, Xworm Among Week’s Top Malware Threats

Next Post

CEVA Logistics Data Breach Exposes Valve Steam Hardware Buyers’ Information

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Kimsuky deploys AsyncRAT via AI lures, local LLMs, and GitHub C2
August 10, 2026
Ransomware Targets Managers for Data Theft and Network Infiltration
August 10, 2026
DuckDNS abused to distribute VBS/PowerShell RATs
August 10, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Emy Elsamnoudy
Emy Elsamnoudy
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us