news.mlab.sh
Back to the feed
malware

EDR killers explained: Beyond the drivers

High
Summary

This article analyzes the increasing use of "EDR killers" in modern ransomware attacks. These tools, often based on vulnerable drivers or custom scripts, are deployed by affiliates to disrupt endpoint detection and response (EDR) systems, creating a window for ransomware encryptors to operate. The analysis, based on ESET telemetry, reveals a diverse landscape of EDR killers, highlighting the challenges of attribution and the evolving tactics employed by ransomware groups, particularly the rise of "packer as a service" and commercialized kits.

Read the full article at WeLiveSecurity

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.