{"id":167105,"date":"2024-08-15T20:12:37","date_gmt":"2024-08-15T20:12:37","guid":{"rendered":"https:\/\/securityaffairs.com\/?p=167105"},"modified":"2024-08-15T20:12:40","modified_gmt":"2024-08-15T20:12:40","slug":"ransomhub-tool-kill-edr-software","status":"publish","type":"post","link":"https:\/\/securityaffairs.com\/167105\/cyber-crime\/ransomhub-tool-kill-edr-software.html","title":{"rendered":"A group linked to RansomHub operation employs EDR-killing tool EDRKillShifter"},"content":{"rendered":"
<\/div>\n

A cybercrime group linked to the RansomHub ransomware was spotted using a new tool designed to kill EDR software.<\/h2>\n\n\n\n

Sophos reports that a cybercrime group, likely linked to the RansomHub<\/a> ransomware operation, has been observed using a new EDR-killing utility that can terminate endpoint detection and response software on compromised systems. The researchers called the new tool EDRKillShifter.\u00a0<\/p>\n\n\n\n

The tool was discovered during the investigation of an incident that occurred in May, it was used to terminate Sophos solution on the targeted computer, however, the experts said the tool failed. <\/p>\n\n\n\n

The experts believe that EDRKillShifter is being used by multiple attackers. <\/p>\n\n\n\n

“During the incident in May, the threat actors \u2013 we estimate with moderate confidence that this tool is being used by multiple attackers \u2014 attempted to use EDRKillShifter to terminate Sophos protection on the targeted computer, but the tool failed.” reads the report<\/strong><\/a> published by Sophos. “They then attempted to run the ransomware executable on the machine they controlled, but that also failed when the endpoint agent\u2019s CryptoGuard feature was triggered.”<\/em><\/p>\n\n\n\n

The EDRKillShifter tool is a loader executable used to deliver vulnerable drivers (a BYOVD<\/a> tool) that can be exploited by attackers. It operates in three steps:<\/p>\n\n\n\n