惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

雷峰网
雷峰网
MongoDB | Blog
MongoDB | Blog
D
Docker
Martin Fowler
Martin Fowler
人人都是产品经理
人人都是产品经理
GbyAI
GbyAI
Jina AI
Jina AI
酷 壳 – CoolShell
酷 壳 – CoolShell
M
MIT News - Artificial intelligence
腾讯CDC
阮一峰的网络日志
阮一峰的网络日志
H
Hackread – Cybersecurity News, Data Breaches, AI and More
N
Netflix TechBlog - Medium
B
Blog RSS Feed
云风的 BLOG
云风的 BLOG
Blog — PlanetScale
Blog — PlanetScale
Vercel News
Vercel News
The Cloudflare Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
有赞技术团队
有赞技术团队
G
Google Developers Blog
Stack Overflow Blog
Stack Overflow Blog
I
InfoQ
U
Unit 42

Google adds end-to-end Gmail encryption to Android, iOS devices for enterprises | CSO Online

Die besten DAST- & SAST-Tools CISA mulls new three-day remediation deadline for critical flaws CISA pushes critical infrastructure operators to prepare to work in isolation CISOs step up to the security workforce challenge 10 Anzeichen für einen schlechten CSO Anthropic Mythos spurs White House to weigh pre-release reviews for high-risk AI models Security agencies draw red lines around agentic AI deployments The fake IT worker problem CISOs can’t ignore How CISOs should utilize data security posture management to inform risk Was ist ein Botnet? Human-centric failures: Why BEC continues to work despite MFA Just 34% of cyber pros plan to stick with their current employer Managing OT risk at scale: Why OT cyber decisions are leadership decisions 4 ways to prepare your SOC for agentic AI ‘Trivial’ exploit can give attackers root access to Linux kernel Bank regulator sounds warning over cybersecurity threat posed by AI models Dismantle implicit trust in OT networks, CISA tells critical infrastructure operators Max-severity RCE flaw found in Google Gemini CLI Stopping the quiet drift toward excessive agency with re-permissioning ODNI to CISOs on threat assessments: You’re on your own 10 wichtige Security-Eigenschaften: So setzen Sie die Kraft Ihres IT-Sicherheitstechnik-Teams frei Researchers unearth industrial sabotage malware that predated Stuxnet by 5 years AWS leans on prior ingenuity to face future AI and quantum threats What it takes to win that CSO role Third Party Risk Management: So vermeiden Sie Compliance-Unheil Critical Cursor bug could turn routine Git into RCE Securing RAG pipelines in enterprise SaaS What CISOs need to get right as identity enters the agentic era Stopping AiTM attacks: The defenses that actually work after authentication succeeds EDR-Software – ein Kaufratgeber
Threat actor adds advanced 'EDR killer' tools to ransomwa...
John E. Dunn · 2026-06-20 · via Google adds end-to-end Gmail encryption to Android, iOS devices for enterprises | CSO Online

Traditional EDR defense is under threat after a criminal group added a sophisticated capability to shut it down, warns ESET.

One of the world’s top ransomware groups has given its criminal affiliates access to advanced tools capable of successfully disabling many of today’s enterprise endpoint detection and response (EDR) products, new research by security company ESET has found.

The group in question is The Gentlemen, which, since its appearance last year using this moniker, has become one of the most successful ransomware-as-a-service (RaaS) platforms thanks to a business model that gives affiliates an unusually generous 90/10 revenue split.

In May, the group’s servers were breached by an unknown attacker, who posted materials subsequently analyzed by researchers to uncover deeper insights into the group’s operation.

One tactic that ESET thinks hasn’t had the attention it deserves is the growing importance of ‘EDR killers’ in the estimated 300 ransomware attacks carried out via The Gentlemen platform.

EDR killers, tools which attempt to bypass or disable PC and server endpoint security agents during a cyberattack, are not new, but have gradually increased in number and sophistication. However, the barrier to using them in a ransomware context is that an affiliate still needs to develop or source their own EDR killer tool, a major undertaking given the large number of EDR products in use by defenders.

The leak confirmed ESET’s suspicion that The Gentlemen had developed its own EDR killer framework, dubbed ‘GentleKiller’, which gives affiliates access to a wide range of sophisticated EDR killer routines without having to any of the work themselves. The Gentlemen also integrates well-known third party tools such as HexKiller, ThrottleBlood, and HavocKiller.

Bring your own vulnerable driver

According to ESET researcher Jakub Souček, the effect of this has been to democratize EDR killing capabilities, which have become essential to evading enterprise defenses.

“By providing such tools for affiliates, they lower the entry barrier for less skilled affiliates, who, on top of the encryptor, also receive everything they need to perform intrusions. This naturally expands the affiliate pool and enables consistent encryptor deployment,” Souček said via email.

Across a total of eight variants, a central element of the framework was the ability to quickly deploy new bring your own vulnerable driver (BYOVD) proofs-of-concept used to gain kernel-level privileges after loading a vulnerable driver into memory. The technology was bundled with evasions for 400 EDR processes from 48 different vendors.

The principle behind BYOVD is simple enough: once an attacker has gained admin privileges through an account takeover, they load a legitimate, but old and vulnerable vendor driver, inside which lies an exploitable vulnerability. This extends the power of admin control to kernel level, allowing them to target the EDR drivers in a direct way.

EDR tools’ vulnerability to a newer generation of evasion techniques has been known for some time; a 2024 study by security company Trellix highlighted this weakness, and earlier this year, another security vendor, Huntress, reported a recent case in which BYOVD had been used to load and target a vulnerable old driver to shut down EDR defenses.

“The biggest defense obstacle is the fact that EDR killers rely on vulnerable non-malicious drivers that are often still used legitimately,” noted Souček.

To defend against this, enterprises should enforce protections such as Hypervisor-Protected Code Integrity (HVCI) and Kernel-mode Code Integrity (KMCI), which make it more difficult for old or unsafe drivers to be loaded, he said.

According to Souček, “companies should also enforce strict allow and block driver policies, including via custom rules that fit their organization, continuously audit and remove unnecessary drivers, and ensure vulnerable drivers are updated or eliminated. Preventing the installation of such drivers renders the EDR killer benign.”

SUBSCRIBE TO OUR NEWSLETTER

From our editors straight to your inbox

Get started by entering your email address below.