Close Menu
  • Homepage
  • News
  • Cloud & AI
  • ECommerce
  • Entertainment
  • Finance
  • Opinion
  • Podcast
  • Contact

Subscribe to Updates

Get the latest technology news from TechFinancials News about FinTech, Tech, Business, Telecoms and Connected Life.

What's Hot

ZIOX is Creating a New Wave in the Altcoin Market

2025-09-01

Huawei And Government Partners Mark Fourth Year Of Women In Tech Digital Skills Training

2025-09-01

Smart EV Charging Launches In SA To Tackle Unique Energy Challenges

2025-09-01
Facebook X (Twitter) Instagram
Trending
  • ZIOX is Creating a New Wave in the Altcoin Market
Facebook X (Twitter) Instagram YouTube LinkedIn WhatsApp RSS
TechFinancials
  • Homepage
  • News
  • Cloud & AI
  • ECommerce
  • Entertainment
  • Finance
  • Opinion
  • Podcast
  • Contact
TechFinancials
Home»Connected Life»Ransomware Gangs Use New Malware To Destroy Security Software
Connected Life

Ransomware Gangs Use New Malware To Destroy Security Software

Sophos identifies EDRKillShifter as Troj/KillAV-KG and uses behavioral protection rules to block the system calls that enable defense evasion and privilege escalation.
Gugu LourieBy Gugu Lourie2024-08-16No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Email
Criminal hacking system unsuccessfully
Criminal hacking system unsuccessfully. Designed by Freepik
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

RansomHub ransomware operators have introduced a new malware, dubbed EDRKillShifter, to cripple security defenses in Bring Your Own Vulnerable Driver (BYOVD) attacks.

Discovered by Sophos in May 2024, the malware exploits a legitimate but vulnerable driver to escalate privileges, disable Endpoint Detection and Response (EDR) tools, and seize control of targeted systems.

During the incident in May, the threat actors – we estimate with moderate confidence that this tool is being used by multiple attackers — attempted to use EDRKillShifter to terminate Sophos protection on the targeted computer, but the tool failed,” Andreas Klopsch, a threat researcher at Sophos, wrote in the company’s blog.

“They then attempted to run the ransomware executable on the machine they controlled, but that also failed when the endpoint agent’s CryptoGuard feature was triggered.”

How EDRKillShifter Works

EDRKillShifter functions as a “loader” executable, designed to deliver a legitimate yet vulnerable driver—a tactic known as Bring Your Own Vulnerable Driver (BYOVD). Depending on the attacker’s needs, it can deploy various driver payloads.

The execution process involves three key steps:

  1. The attacker runs EDRKillShifter with a command line that includes a specific password.
  2. If the correct password is provided, the executable decrypts an embedded resource named BIN and loads it into memory.
  3. The BIN code then unpacks and executes the final payload, which is written in Go. This payload drops and exploits a vulnerable, legitimate driver to gain elevated privileges and disable EDR protections.

Mitigations and Advice

Sophos identifies EDRKillShifter as Troj/KillAV-KG and uses behavioral protection rules to block the system calls that enable defense evasion and privilege escalation. Businesses and individuals can further protect against driver abuse with these steps:

  1. Enable Tamper Protection: Ensure your endpoint security product has tamper protection enabled. This adds a crucial layer of defense against attacks. If you’re using Sophos products, activate tamper protection if it isn’t already turned on.
  2. Maintain Strong Windows Security Hygiene: This type of attack relies on the attacker gaining elevated privileges or admin rights. Enforcing strict separation between user and admin privileges can make it harder for attackers to load malicious drivers.
  3. Keep Your System Updated: Microsoft has been rolling out updates that de-certify signed drivers previously exploited in attacks. Regularly updating your system helps protect against these vulnerabilities.

ransomware Sophos
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Gugu Lourie
  • Website

Related Posts

Please Call Me: After 25 Years, Will SCA’s New Bench Silence ConCourt?

2025-08-26

How Will Spaza Market Benefit Users, Traders And SMEs?

2025-08-25

Disaster-Proofing the Stack: Why Industries Are Failing the Infrastructure Test

2025-08-21

SUISO, ECEC Signs BEP Contract For R31.5bn Coal-to-Fertiliser Project

2025-08-19

Vodacom Wins Court Approval for Maziv Deal, Awaits ICASA’s Final Ruling

2025-08-15
10.0

Volvo EX30 Cross Country: The Ultimate Glamping EV For SA Adventurers

2025-08-14

Nedbank Buys iKhokha In R1.6Bln Deal To Strengthen SME Support

2025-08-13

Zero Carbon Charge Urges Minister Tau To Slash EV Import Taxes

2025-08-12

A Wake-Up Call: Unregulated Buy Now, Pay Later Could Trigger A Financial Crisis

2025-08-11
Leave A Reply Cancel Reply

DON'T MISS
Breaking News

Smart EV Charging Launches In SA To Tackle Unique Energy Challenges

 In a major step for electric transport, the STS Tech Group has launched ‘Smart EV’,…

BankservAfrica Rebrands As PayInc

2025-08-29

Government Pensions Administration Agency CEO Placed On Precautionary Suspension

2025-08-26

Airtel Africa & Vodacom Forge Landmark Infrastructure Partnership

2025-08-12
Stay In Touch
  • Facebook
  • Twitter
  • YouTube
  • LinkedIn
OUR PICKS

Electric Family Adventure: Conquering The N3 In Volvo’s Silent Luxury EX90

2025-09-01

R6.5M Range Rover SV Polar Night: Only 5 for SA

2025-09-01

Vodacom Invests R400M To Expand Network In Free State And Northern Cape

2025-08-26

Elon Musk’s Starlink Backs BEE Equity Equivalents, Not 30% Ownership

2025-08-18

Subscribe to Updates

Get the latest tech news from TechFinancials about telecoms, fintech and connected life.

About Us

TechFinancials delivers in-depth analysis of tech, digital revolution, fintech, e-commerce, digital banking and breaking tech news.

Facebook X (Twitter) Instagram YouTube LinkedIn WhatsApp Reddit RSS
Our Picks

ZIOX is Creating a New Wave in the Altcoin Market

2025-09-01

Huawei And Government Partners Mark Fourth Year Of Women In Tech Digital Skills Training

2025-09-01

Smart EV Charging Launches In SA To Tackle Unique Energy Challenges

2025-09-01
Recent Posts
  • ZIOX is Creating a New Wave in the Altcoin Market
  • Huawei And Government Partners Mark Fourth Year Of Women In Tech Digital Skills Training
  • Smart EV Charging Launches In SA To Tackle Unique Energy Challenges
  • Chainlink, VeChain, Or Remittix? Which Of These Is Predicted To Jump Over 20x In September
  • Shiba Inu Latest News: Top 10 Shiba Inu Whale Backs Remittix As History Could Be Repeated With 1,000X ROI
TechFinancials
RSS Facebook X (Twitter) LinkedIn YouTube WhatsApp
  • Homepage
  • Newsletter
  • Contact
  • Advertise
  • Privacy Policy
  • About
© 2025 TechFinancials. Designed by TFS Media.

Type above and press Enter to search. Press Esc to cancel.

Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.