www.extrahop.com Emerging EDR Killer Tool Targeting Ransomware Groups
Article Content
- •The EDR killer tool is used by at least eight ransomware groups.
- •It disables EDR solutions, creating blind spots for defenders.
- •The tool is an evolution of RansomHub's EDRKillShifter and exploits vulnerabilities.
A new malicious tool, referred to as the EDR killer, is being actively used by at least eight ransomware groups, including Blacksuit and Medusa, to disable endpoint detection and response (EDR) solutions. This tool is believed to be an evolution of the EDRKillShifter developed by RansomHub, which allows ransomware operators to bypass traditional defenses. Reports indicate that the EDR killer creates a 'blind spot' for defenders by disabling security controls before deploying ransomware or other malware. Additionally, the tool has been packed using the HeartCrypt packer-as-a-service, and one attack involved exploiting a zero-day vulnerability in SimpleHelp to gain initial access. The current status of this tool indicates a growing trend among ransomware actors to leverage advanced evasion techniques, posing a significant threat to organizations relying on EDR solutions.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track MedusaLocker, FIN7 and Cobalt Strike in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which ransomware groups are using the EDR killer?
How does the EDR killer disable security controls?
What should organizations do to protect against this threat?
Continue Reading
Multiple Ransomware Attacks Target Various Organizations In September 2026, multiple organizations, including watchops.com and geekybunch.com, were reported as victims of ransomware attacks by the group known as 'unsafe'. The incidents were listed on dark web leak sites, but details regarding the nature of the attacks, such as data encryption or theft, remain vague. The…
[MEDUSALOCKER] Ransomware Attacks Seznam and Aokkef On September 23, 2026, the MedusaLocker ransomware group listed two organizations as victims: Seznam from the Czech Republic and Aokkef from France. Seznam's listing claims that 115 email addresses were extracted, while Aokkef's listing states that 137 email records were taken. Both incidents are described as data…