By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Hackers Repurpose RansomHub’s EDRKillShifter in Medusa, BianLian, and Play Attacks
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Hackers Repurpose RansomHub’s EDRKillShifter in Medusa, BianLian, and Play Attacks
Tech News

Hackers Repurpose RansomHub’s EDRKillShifter in Medusa, BianLian, and Play Attacks

By Viral Trending Content 4 Min Read
Share
SHARE

Mar 27, 2025Ravie LakshmananEndpoint Security / Ransomware

RansomHub's EDRKillShifter

A new analysis has uncovered connections between affiliates of RansomHub and other ransomware groups like Medusa, BianLian, and Play.

The connection stems from the use of a custom tool that’s designed to disable endpoint detection and response (EDR) software on compromised hosts, according to ESET. The EDR killing tool, dubbed EDRKillShifter, was first documented as used by RansomHub actors in August 2024.

EDRKillShifter accomplishes its goals by means of a known tactic called Bring Your Own Vulnerable Driver (BYOVD) that involves using a legitimate but vulnerable driver to terminate security solutions protecting the endpoints.

Cybersecurity

The idea with using such tools is to ensure the smooth execution of the ransomware encryptor without it being flagged by security solutions.

“During an intrusion, the goal of the affiliate is to obtain admin or domain admin privileges,” ESET researchers Jakub Souček and Jan Holman said in a report shared with The Hacker News.

“Ransomware operators tend not to do major updates of their encryptors too often due to the risk of introducing a flaw that could cause issues, ultimately damaging their reputation. As a result, security vendors detect the encryptors quite well, which the affiliates react to by using EDR killers to ‘get rid of’ the security solution just before executing the encryptor.”

RansomHub's EDRKillShifter

What’s notable here is that a bespoke tool developed by the operators of RansomHub and offered to its affiliates – something of a rare phenomenon in itself – is being used in other ransomware attacks associated with Medusa, BianLian, and Play.

This aspect assumes special significance in light of the fact that both Play and BianLian operate under the closed RaaS model, wherein the operators are not actively looking to hire new affiliates and their partnerships are based on long-term mutual trust.

“Trusted members of Play and BianLian are collaborating with rivals, even newly emerged ones like RansomHub, and then repurposing the tooling they receive from those rivals in their own attacks,” ESET theorized. “This is especially interesting, since such closed gangs typically employ a rather consistent set of core tools during their intrusions.”

It’s being suspected that all these ransomware attacks have been carried out by the same threat actor, dubbed QuadSwitcher, who is likely related to Play the closest owing to similarities in tradecraft typically associated with Play intrusions.

EDRKillShifter has also been observed being used by another individual ransomware affiliate known as CosmicBeetle as part of three different RansomHub and fake LockBit attacks.

Cybersecurity

The development comes amid a surge in ransomware attacks using BYOVD techniques to deploy EDR killers on compromised systems. Last year, the ransomware gang known as Embargo was discovered using a program called MS4Killer to neutralize security software. As recently as this month, the Medusa ransomware crew has been linked to a custom malicious driver codenamed ABYSSWORKER.

“Threat actors need admin privileges to deploy an EDR killer, so ideally, their presence should be detected and mitigated before they reach that point,” ESET said.

“Users, especially in corporate environments, should ensure that the detection of potentially unsafe applications is enabled. This can prevent the installation of vulnerable drivers.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

Our Favorite Amazon Streaming Stick Is Almost Half Off

How is Australia working to make data centres more sustainable?

Google Pixel 11 Design Leaked: Two key Changes

Are Biofuels Worse Than Fossil Fuels?

Critical Citrix NetScaler memory flaw actively exploited in attacks

TAGGED: Cyber Security, Cybercrime, Cybersecurity, EDR, endpoint security, hacking tool, hreat Intelligence, Internet, Malware, RaaS, Ransomware
Share This Article
Facebook Twitter Copy Link
Previous Article Even More Venmo Accounts Tied to Trump Officials in Signal Group Chat Left Data Public
Next Article Dollar Tree sold Family Dollar at a massive discount for just $1 billion. Just a decade ago, it was worth $9 billion
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Is the EU’s own veto right a leverage tool? Ask the Euronews AI chatbot
World News
Bitcoin Miners Are Coming Back—Hashrate Jumps 12.5% From March Lows
Crypto
Celine Dion Then & Now: Photos of the ‘My Heart Will Go On’ Songstress
Celebrity
Monster Hunter Stories 3: Twisted Reflection Drops New Accolades Trailer
Gaming News
Our Favorite Amazon Streaming Stick Is Almost Half Off
Tech News
Leafs Score Today: Latest Toronto Maple Leafs Game Result and Key Stats
Sports
US Stocks: S&P, Nasdaq end lower as investors weigh Middle East conflict outlook
Business

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Investing £5 a day could help me build a second income of £329 a month!

Brussels unveils plans for a European Degree but struggles to explain why

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
Trump evokes more anger and fear from Democrats than Biden does from Republicans, AP-NORC poll shows
March 28, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?