Ransomware attackers introduce new EDR killer to their arsenal
#1
Quote:Sophos analysts recently encountered a new EDR-killing utility being deployed by a criminal group who were trying to attack an organization with ransomware called RansomHub. While the ransomware attack ultimately was unsuccessful, the postmortem analysis of the attack revealed the existence of a new tool designed to terminate endpoint protection software. We are calling this tool EDRKillShifter. 


Full Article_Source
 
RansomHub's New Malware EDRKillShifter

Additional Info HERE
[-] The following 2 users say Thank You to dhruv2193 for this post:
  • harlan4096, jasonX
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
WinRAR 7.21 (stable release)
WinRAR 7.21 (stabl...harlan4096 — 08:18
Opera 31.0.5877.5
Dear Opera Users! ...harlan4096 — 08:17
Vivaldi 7.9 Build 3970.60
Vivaldi 7.9 Build ...harlan4096 — 08:16
PowerToys 0.99.1
Release v0.99.1 ...harlan4096 — 08:15
Is your car spying on you?
How law enforcemen...harlan4096 — 08:14

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
No upcoming birthdays.

[-]
Online Staff
There are no staff members currently online.

>