Ransomware Actors Expand EDR Killer Tactics Beyond Vulnerable Drivers
Ransomware attackers have broadened their strategies to overcome endpoint security measures, advancing beyond the use of vulnerable drivers. The Bring Your Own Vulnerable Driver (BYOVD) method, once a primary approach, has been supplemented with…
Ransomware attackers have broadened their strategies to overcome endpoint security measures, advancing beyond the use of vulnerable drivers. The Bring Your Own Vulnerable Driver (BYOVD) method, once a primary approach, has been supplemented with script-based tools, misuse of anti-rootkit software, and driverless methods to disable security products before file encryption.
This change emphasizes the operational need for ransomware affiliates to secure a brief, dependable period to execute their encryptors without interference. Instead of attempting to conceal encryptors from detection, attackers focus on disabling security protections entirely.
Prevalence and Evolution of EDR Killers
Endpoint Detection and Response (EDR) killers, tools designed to disable security software, are now integral to modern ransomware strategies. Research indicates this trend is accelerating across both large and small ransomware groups. Analysts have identified approximately 90 active EDR killers used by various ransomware gangs.
54 BYOVD-based tools using 35 distinct vulnerable drivers 7 script-based tools 15 tools exploiting legitimate anti-rootkit or freely available software
The EDR killer ecosystem has matured into a commercially driven market, where these tools are developed, sold, and adapted targeting a range of security vendors.
Ransomware attackers have broadened their strategies to overcome endpoint security measures, advancing beyond the use of vulnerable drivers.
Victims of ransomware attacks encounter scenarios where security tools are neutralized before the encryption process begins. This is evident with groups like Akira, Medusa, Qilin, RansomHouse, and DragonForce, which utilize commercially available EDR killers sourced from underground markets.
AbyssKiller, combining the ABYSSWORKER rootkit with a HeartCrypt-packed loader CardSpaceKiller, frequently associated with attacks by Akira, Medusa, and MedusaLocker
Technical Sophistication in Detection Evasion
EDR killers represent the primary method for defense evasion in ransomware operations, with attackers investing in these tools rather than in the encryption software itself. This division of labor has led to the development of powerful tools accessible even to attackers with limited technical skills.
Separating the killer tool from the driver it abuses Using products like VX Crypt and HeartCrypt for obfuscation Employing code protection tools such as VMProtect and Themida
Specific tools demonstrate additional sophistication, such as SmilingKiller's use of control-flow flattening and CardSpaceKiller's reliance on call-by-hash resolution and string obfuscation.
Organizations should implement driver blocking as a foundational measure. Security teams should monitor for suspicious driver installations and maintain blocklists to identify known vulnerabilities. A layered detection strategy through a managed detection and response provider or an internal SOC team is essential, as attackers continuously adapt their methods.
Restricting high-privilege access and maintaining network segmentation can minimize the time attackers require to deploy their tools. Strong endpoint telemetry is crucial to maintaining visibility even when one layer of defense is compromised.
Based on reporting by Cyber Security News.
