Close Menu
  • Homepage
  • News
  • Cloud & AI
  • ECommerce
  • Entertainment
  • Finance
  • Opinion
  • Podcast
  • Contact

Subscribe to Updates

Get the latest technology news from TechFinancials News about FinTech, Tech, Business, Telecoms and Connected Life.

What's Hot

Monerohub.io Launches as the Essential Central Gateway to the Monero Ecosystem

2026-01-29

Luxbit.AI Introduces Streamlined Withdrawal Framework to Enhance User Trust and Accessibility

2026-01-29

SARB Holds Repo Rate Steady in Cautious Monetary Policy Decision

2026-01-29
Facebook X (Twitter) Instagram
Trending
  • Monerohub.io Launches as the Essential Central Gateway to the Monero Ecosystem
Facebook X (Twitter) Instagram YouTube LinkedIn WhatsApp RSS
TechFinancials
  • Homepage
  • News
  • Cloud & AI
  • ECommerce
  • Entertainment
  • Finance
  • Opinion
  • Podcast
  • Contact
TechFinancials
Home»Connected Life»Ransomware Gangs Use New Malware To Destroy Security Software
Connected Life

Ransomware Gangs Use New Malware To Destroy Security Software

Sophos identifies EDRKillShifter as Troj/KillAV-KG and uses behavioral protection rules to block the system calls that enable defense evasion and privilege escalation.
Gugu LourieBy Gugu Lourie2024-08-16No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Email
Criminal hacking system unsuccessfully
Criminal hacking system unsuccessfully. Designed by Freepik
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

RansomHub ransomware operators have introduced a new malware, dubbed EDRKillShifter, to cripple security defenses in Bring Your Own Vulnerable Driver (BYOVD) attacks.

Discovered by Sophos in May 2024, the malware exploits a legitimate but vulnerable driver to escalate privileges, disable Endpoint Detection and Response (EDR) tools, and seize control of targeted systems.

During the incident in May, the threat actors – we estimate with moderate confidence that this tool is being used by multiple attackers — attempted to use EDRKillShifter to terminate Sophos protection on the targeted computer, but the tool failed,” Andreas Klopsch, a threat researcher at Sophos, wrote in the company’s blog.

“They then attempted to run the ransomware executable on the machine they controlled, but that also failed when the endpoint agent’s CryptoGuard feature was triggered.”

How EDRKillShifter Works

EDRKillShifter functions as a “loader” executable, designed to deliver a legitimate yet vulnerable driver—a tactic known as Bring Your Own Vulnerable Driver (BYOVD). Depending on the attacker’s needs, it can deploy various driver payloads.

The execution process involves three key steps:

  1. The attacker runs EDRKillShifter with a command line that includes a specific password.
  2. If the correct password is provided, the executable decrypts an embedded resource named BIN and loads it into memory.
  3. The BIN code then unpacks and executes the final payload, which is written in Go. This payload drops and exploits a vulnerable, legitimate driver to gain elevated privileges and disable EDR protections.

Mitigations and Advice

Sophos identifies EDRKillShifter as Troj/KillAV-KG and uses behavioral protection rules to block the system calls that enable defense evasion and privilege escalation. Businesses and individuals can further protect against driver abuse with these steps:

  1. Enable Tamper Protection: Ensure your endpoint security product has tamper protection enabled. This adds a crucial layer of defense against attacks. If you’re using Sophos products, activate tamper protection if it isn’t already turned on.
  2. Maintain Strong Windows Security Hygiene: This type of attack relies on the attacker gaining elevated privileges or admin rights. Enforcing strict separation between user and admin privileges can make it harder for attackers to load malicious drivers.
  3. Keep Your System Updated: Microsoft has been rolling out updates that de-certify signed drivers previously exploited in attacks. Regularly updating your system helps protect against these vulnerabilities.

ransomware Sophos
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Gugu Lourie
  • Website

Related Posts

The EX60: A Volvo That Talks Back

2026-01-20

Ransomware: What It Is And Why It’s Your Problem

2026-01-19

New SITA CEO Vows: Faster Digital State, Stronger Security For All

2026-01-15

Stablecoins Are Gaining Ground As Digital Currency In Africa: How To Avoid Risks

2026-01-13

New Volvo EX60 Promises Up to 810km Range With A Quick Recharge

2026-01-08

SIU, Hawks In Coordinated Raids On Alleged R161M Covid-19 TERS Fraud Syndicate

2025-12-11

VERAFIED And Nolo Phiri Lead A New Digital Truth Movement In The Age Of AI Misinformation

2025-12-03

Can AI Be Inclusive Without Africa?

2025-12-01

Crypto Payments Startup Oobit Accelerates Global Expansion Strategy with Launch in South Africa

2025-11-28
Leave A Reply Cancel Reply

DON'T MISS
Breaking News

SARB Holds Repo Rate Steady in Cautious Monetary Policy Decision

In a world described as fractured and fragile, the South African Reserve Bank (SARB) has…

How Many Smart ID Cards Were Issued In South Africa in 2025

2026-01-29

Huawei Says The Next Wave Of Infrastructure Investment Must Include People, Not Only Platforms

2026-01-21

South Africa: Best Starting Point In Years, With 3 Clear Priorities Ahead

2026-01-12
Stay In Touch
  • Facebook
  • Twitter
  • YouTube
  • LinkedIn
OUR PICKS

How a Major Hotel Group Is Electrifying South Africa’s Travel

2026-01-29

Volvo C70: 30 Years Of The Car That Changed The Way Volvo Looked

2026-01-29

The EX60 Cross Country: Built For The “Go Anywhere” Attitude

2026-01-23

Mettus Launches Splendi App To Help Young South Africans Manage Their Credit Health

2026-01-22

Subscribe to Updates

Get the latest tech news from TechFinancials about telecoms, fintech and connected life.

About Us

TechFinancials delivers in-depth analysis of tech, digital revolution, fintech, e-commerce, digital banking and breaking tech news.

Facebook X (Twitter) Instagram YouTube LinkedIn WhatsApp Reddit RSS
Our Picks

Monerohub.io Launches as the Essential Central Gateway to the Monero Ecosystem

2026-01-29

Luxbit.AI Introduces Streamlined Withdrawal Framework to Enhance User Trust and Accessibility

2026-01-29

SARB Holds Repo Rate Steady in Cautious Monetary Policy Decision

2026-01-29
Recent Posts
  • Monerohub.io Launches as the Essential Central Gateway to the Monero Ecosystem
  • Luxbit.AI Introduces Streamlined Withdrawal Framework to Enhance User Trust and Accessibility
  • SARB Holds Repo Rate Steady in Cautious Monetary Policy Decision
  • Alleged R1 Billion International Scam Syndicate Members Arrested
  • How Many Smart ID Cards Were Issued In South Africa in 2025
TechFinancials
RSS Facebook X (Twitter) LinkedIn YouTube WhatsApp
  • Homepage
  • Newsletter
  • Contact
  • Advertise
  • Privacy Policy
  • About
© 2026 TechFinancials. Designed by TFS Media. TechFinancials brings you trusted, around-the-clock news on African tech, crypto, and finance. Our goal is to keep you informed in this fast-moving digital world. Now, the serious part (please read this): Trading is Risky: Buying and selling things like cryptocurrencies and CFDs is very risky. Because of leverage, you can lose your money much faster than you might expect. We Are Not Advisors: We are a news website. We do not provide investment, legal, or financial advice. Our content is for information and education only. Do Your Own Research: Never rely on a single source. Always conduct your own research before making any financial decision. A link to another company is not our stamp of approval. You Are Responsible: Your investments are your own. You could lose some or all of your money. Past performance does not predict future results. In short: We report the news. You make the decisions, and you take the risks. Please be careful.

Type above and press Enter to search. Press Esc to cancel.

Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.