Ransomware attackers introduce new EDR killer to their arsenal
#1
Quote:Sophos analysts recently encountered a new EDR-killing utility being deployed by a criminal group who were trying to attack an organization with ransomware called RansomHub. While the ransomware attack ultimately was unsuccessful, the postmortem analysis of the attack revealed the existence of a new tool designed to terminate endpoint protection software. We are calling this tool EDRKillShifter. 


Full Article_Source
 
RansomHub's New Malware EDRKillShifter

Additional Info HERE
[-] The following 2 users say Thank You to dhruv2193 for this post:
  • harlan4096, jasonX
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Microsoft releases KB5070773 out of band...
Microsoft has rele...harlan4096 — 10:23
AdGuard for iOS v4.5.14
AdGuard for iOS v4...harlan4096 — 08:49
AVLab.pl - Advanced In-The-Wild Malware ...
Hi Community We...harlan4096 — 08:48
K. STANDARD / PLUS / PREMIUM 21.23
K. STANDARD / PLUS /...harlan4096 — 07:12
Notepad++ 8.8.7
Notepad++ 8.8.7 ...harlan4096 — 07:09

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
avatar (47)Michaelaceve
avatar (37)QuadirLigh
avatar (38)Mblippek
avatar (44)viecontAceve
avatar (40)Michaelcrini

[-]
Online Staff
There are no staff members currently online.

>