RansomHub Group Introduces Tool to Disable Endpoint Security in Latest Attacks
A new cyber threat has emerged, connected to the RansomHub ransomware, designed to shut down security software on infected computers. Named EDRKillShifter by the cybersecurity company Sophos, this tool joins other similar programs that disable security measures.
Sophos discovered EDRKillShifter during a failed ransomware attack in May 2024. This tool acts as a delivery system for vulnerable drivers, which can be misused to bypass security protections. Security expert Andreas Klopsch explained that EDRKillShifter can load different harmful drivers depending on what the attackers need.
RansomHub, which is thought to be a new version of the Knight ransomware, first appeared in February 2024. It takes advantage of security weaknesses to gain access and installs legitimate remote-control software, like Atera and Splashtop, to maintain control over infected systems.
Source: RansomHub Group Deploys New EDR-Killing Tool in Latest Cyber Attacks (thehackernews.com)
Comments
Woah, Thanks for the news, anyway, kinda curious - How to mitigate this?
August 21, 2024 21:05 (on 8/22/24)
Hello BridzG, to mitigate this, it's recommended to keep systems up-to-date, enable tamper protection in EDR software, and practice strong hygiene for Windows security roles.
August 21, 2024 21:13 (on 8/22/24)