Shanya EDR Killer: The New Favorite Tool for Ransomware Operators
A newly developed "packer-as-a-service" tool, Shanya, has surfaced in the cybercriminal landscape, becoming a favored instrument for major ransomware groups aiming to bypass endpoint security measures.
A newly developed "packer-as-a-service" tool, Shanya, has surfaced in the cybercriminal landscape, becoming a favored instrument for major ransomware groups aiming to bypass endpoint security measures.
Research from Sophos indicates that Shanya represents an advancement in the "EDR killer" market, following in the footsteps of previous tools like HeartCrypt. The malware is engineered to disable security monitoring and terminate protection processes, facilitating the deployment of ransomware payloads such as Akira, Medusa, and Qilin without obstruction.
First identified in late 2024 on Russian-language underground forums, the tool is marketed as "VX Crypt" by an entity known as "Shanya." The service is noted for its sophisticated evasion capabilities, including non-standard module loading, unique stub generation per customer, AMSI bypassing, and resistance to sandboxing.
The creators of the malware also claim runtime protection for .NET assemblies and the ability to operate undetected for extended durations, a claim corroborated by recent incidents.
Shanya primarily uses DLL side-loading, a technique where malicious code impersonates legitimate system libraries to deceive trusted applications into executing it.
In analyzed attacks, Shanya often exploits consent.exe , a legitimate Windows User Account Control component, to load a malicious DLL, typically named msimg32.dll . Once active, it employs a "bring your own vulnerable driver" (BYOVD) approach, deploying a legitimate yet vulnerable driver, such as ThrottleStop.sys , alongside a malicious kernel driver.
Shanya's geographic distribution has been global, with detections in all four hemispheres during 2025.
This strategy allows Shanya to gain kernel-level write access by exploiting the vulnerable driver, enabling it to terminate numerous processes and services linked to antivirus and EDR products.
Shanya's geographic distribution has been global, with detections in all four hemispheres during 2025. The loader is highly obfuscated, using "junk code" and API hashing to impede analysis. It conceals its configuration within the Process Environment Block (PEB) and modifies system DLLs in memory to covertly execute its payload.
Throughout 2025, telemetry data has shown Shanya's deployment in various regions, with significant activity in the UAE and parts of Asia.
The tool's most destructive use has been as a precursor to ransomware attacks. Since its initial appearance in a Medusa attack in April 2025, it has become integral to the operations of the Akira ransomware group.
The evolving market for evasion tools suggests that "packer-as-a-service" offerings will remain vital to the ransomware supply chain, underscoring the need for continuous vigilance from cybersecurity defenders.
In September 2025, Shanya was linked to a "ClickFix" campaign targeting the hospitality industry. Attackers used fraudulent Booking.com verification pages to deceive hotel staff into downloading the malware, which then deployed the CastleRAT backdoor.
Security vendors have adapted their detection signatures to identify this threat. Sophos categorizes the packer and its components under the family names ATK/Shanya-B, ATK/Shanya-C, and ATK/Shanya-D.
Based on reporting by GBHackers.
