ESET Analysis: EDR Killers in Ransomware Attacks Beyond Vulnerable Drivers
ESET researchers have released a comprehensive analysis of the EDR killer ecosystem, revealing how ransomware attackers systematically disable Endpoint Detection and Response software. Based on telemetry from nearly 90 active tools, the study highlights that while Bring Your Own Vulnerable Driver (BYOVD) techniques dominate, attackers increasingly utilize legitimate anti-rootkit utilities and driverless methods to disrupt security communications. The report emphasizes that affiliates, rather than ransomware operators, typically select these tools, leading to significant diversity in weaponization and making driver-based attribution misleading. Shared drivers across unrelated codebases further complicate tracking efforts. Additionally, the commercialization of EDR killers as products and potential AI-assisted development, observed in groups like Warlock, are increasing availability and defense complexity. The findings suggest that focusing solely on vulnerable drivers provides an incomplete picture of modern ransomware operations, necessitating broader defensive strategies that account for predictable evasion stages and the separation between tool selection and payload development.
Wire timeline
ESET Analysis: EDR Killers in Ransomware Attacks Beyond Vulnerable Drivers
ESET researchers have released a comprehensive analysis of the EDR killer ecosystem, revealing how ransomware attackers systematically disable Endpoint Detection and Response software. Based on telemetry from nearly 90 active tools, the study highlights that while Bring Your Own Vulnerable Driver (BYOVD) techniques dominate, attackers increasingly utilize legitimate anti-rootkit utilities and driverless methods to disrupt security communications. The report emphasizes that affiliates, rather than ransomware operators, typically select these tools, leading to significant diversity in weaponization and making driver-based attribution misleading. Shared drivers across unrelated codebases further complicate tracking efforts. Additionally, the commercialization of EDR killers as products and potential AI-assisted development, observed in groups like Warlock, are increasing availability and defense complexity. The findings suggest that focusing solely on vulnerable drivers provides an incomplete picture of modern ransomware operations, necessitating broader defensive strategies that account for predictable evasion stages and the separation between tool selection and payload development.
WeLiveSecurity