惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

S
Security @ Cisco Blogs
H
Hacker News: Front Page
P
Privacy International News Feed
N
News and Events Feed by Topic
T
Threatpost
Simon Willison's Weblog
Simon Willison's Weblog
S
Schneier on Security
K
Kaspersky official blog
S
Secure Thoughts
V2EX - 技术
V2EX - 技术
Security Latest
Security Latest
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
www.infosecurity-magazine.com
www.infosecurity-magazine.com
C
CERT Recently Published Vulnerability Notes
L
Lohrmann on Cybersecurity
Jina AI
Jina AI
P
Proofpoint News Feed
AI
AI
雷峰网
雷峰网
T
Tailwind CSS Blog
Engineering at Meta
Engineering at Meta
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
D
Darknet – Hacking Tools, Hacker News & Cyber Security
Recent Commits to openclaw:main
Recent Commits to openclaw:main
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
博客园 - 叶小钗
Webroot Blog
Webroot Blog
Apple Machine Learning Research
Apple Machine Learning Research
SecWiki News
SecWiki News
罗磊的独立博客
N
Netflix TechBlog - Medium
Martin Fowler
Martin Fowler
Google DeepMind News
Google DeepMind News
Cyberwarzone
Cyberwarzone
MongoDB | Blog
MongoDB | Blog
博客园 - Franky
Schneier on Security
Schneier on Security
The GitHub Blog
The GitHub Blog
S
Security Affairs
Blog — PlanetScale
Blog — PlanetScale
Last Week in AI
Last Week in AI
P
Proofpoint News Feed
月光博客
月光博客
D
Docker
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
S
Securelist
W
WeLiveSecurity
T
Troy Hunt's Blog
A
Arctic Wolf
博客园 - 司徒正美

RSS

Events and conferences Events and conferences Events and conferences Events and conferences Events and conferences Events and conferences Events and conferences Events and conferences Events and conferences Events and conferences Events and conferences Events and conferences Events and conferences Vietnam-aligned OceanLotus pivots to spy on domestic targets as it takes a more selective approach abroad, ESET Research finds Events and conferences Canon Canada Partners with ESET to Expand Cybersecurity Services ESET releases 2026 SMB Cyber Readiness Index showing growing confidence but also concerns about AI ESET has been named the only Challenger in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection ESET Research APT Report: China-aligned groups spy in Venezuela and the Gulf, target AI robotics in S. Korea Events and conferences ESET uncovers the expanded arsenal of China-aligned Webworm; European governments targeted ESET reaffirms its global market presence with new European and Asian offices ESET supercharges AI innovation with investment to address rapidly expanding attack surface ESET joins the Agentic AI Foundation to help shape safe, human‑led agentic AI ESET’s Tony Anscombe to Co-Chair NetDiligence Cyber Risk Summit Belarus-aligned FrostyNeighbor attacks Ukrainian government, again — ESET Research discovers ESET Research uncovers CallPhantom scam on Google Play: Fake logs for real money North Korea-aligned APT group ScarCruft compromises gaming platform in supply‑chain espionage attack, ESET Research finds ESET Research discovers new China-aligned group, GopherWhisper: It abuses messaging services Discord, Slack, and Outlook to spy ESET Research: New NGate hides in NFC payment app, possibly built with AI ESET finds that SMBs currently leverage cyber insurance to arm against attacks, report incidents and improve resilience ESET previews new AI security features to secure chatbot communications and AI workflows ESET wins four Global InfoSec Awards at RSAC 2026 ESET receives Intel vPro Certified App status – Delivering performance benefits for business customers while advancing threat detection capability ESET launches Cloud Workload Protection and AI enhancements for ESET PROTECT customers ESET presents six sessions at RSAC 2026 to advance cyber resilience ESET sets new integration with Lumu ESET Endpoint Security for Windows v12 achieves Common Criteria certification ESET PRIVATE showcases custom security solutions at RSAC 2026 ESET launches eCrime reports ESET Research: One of Russia’s most notorious groups, Sednit, resurges with spyware in Ukraine ESET Opens 2026 Women in Cybersecurity Scholarship Applications CRN Honors ESET on Security 100 List for MDR and AI Innovations ESET’s Ryan Grant Named a 2026 CRN Channel Chief ESET Research discovers PromptSpy, the first Android threat to use generative AI ESET Named Finalist for Best Security Company in Expert Insights Awards 2026 ESET’s Tony Anscombe to Speak at NetDiligence Cyber Risk Summit Russian Sandworm group attacks energy company in Poland with DynoWiper, ESET Research discovers Fake dating app used as lure in spyware campaign targeting Pakistan, ESET Research discovers ESET is a Customers’ Choice for Endpoint Protection according to Gartner® Peer Insights™ ESET Research analyzed a critical flaw in Windows Imaging Component, which abuses JPG files ESET Wins CRN’s 2025 Gender Parity Award New Chinese group LongNosedGoblin deploys cyberespionage tools in Southeast Asia and Japan, ESET Research discovers ESET Threat Report: AI-driven attacks on the rise; NFC threats increase and evolve in sophistication Iran’s MuddyWater targets critical infrastructure in Israel and Egypt, masquerades as Snake game – ESET Research discovers ESET Research: Chinese PlushDaemon group compromises network devices for adversary-in-the-middle attacks ESET Research APT Report: Russian attacks surge in Ukraine and Europe; Chinese groups target Latin American governments ESET named a Leader in IDC MarketScape for Consumer Digital Life Protection North Korean Lazarus group targets the drone sector in Europe, likely for espionage, ESET Research discovers ESET Research discovers new spyware posing as messaging apps targeting users in the UAE ESET Enhances Free Cybersecurity Awareness Training + CSAM Resources ESET Research’s deep dive into DeceptiveDevelopment, North Korean crypto theft via fake job offers ESET Research: Russian FSB-linked Gamaredon and Turla team up to target high-profile Ukrainian entities SDSU Athletics x ESET: Proud Partnership for Student-Athlete Success ESET Research discovers UEFI-compatible HybridPetya ransomware capable of Secure Boot bypass ESET at MSP Summit 2025: Field CISO Keynote + XDR Partner Events ESET Named a Strong Performer in Independent Evaluation of MDR Services in Europe ESET Research discovers new Chinese threat group: GhostRedirector manipulates Google, poisons Windows servers with backdoors ESET discovers PromptLock, the first AI-powered ransomware" on page ESET Research: Russian RomCom group exploits new vulnerability, targets companies in Europe and Canada ESET PROTECT Elite is a Security Winner of the 2025 CRN Tech Innovators ESET has strengthened its position in the 2025 Gartner® Magic Quadrant™ for Endpoint Protection Platforms ESET Research uncovers variants of AsyncRAT, popular choice of cybercriminals Meet the 2025 Women in Cybersecurity Scholarship Winners ESET Named a 2025 Gartner® Peer Insights™ Customers’ Choice for Endpoint Protection ESET Named a Notable Provider in latest European MDR Landscape Report ESET Wins 2025 SC Award for Ransomware Remediation ESET Research discovers the first UEFI bootkit for Linux ESET Research discovers Mozilla and Windows zero day & zero click vulnerabilities exploited by Russia-aligned RomCom APT group ESET Research discovers WolfsBane, new Linux cyberespionage backdoor by China-aligned Gelsemium Days after takedown, ESET Research releases analysis of RedLine Stealer infostealer empire ESET releases latest APT report: China-aligned groups expand targeting; Iran advances diplomatic espionage ESET Research discovers new China-aligned APT group CeranaKeeper, which targeted the Thai government ESET Threat Report: Infostealers using AI & banking malware creating deepfake videos to steal money ESET Research: Ebury botnet alive & growing; 400k Linux servers compromised for cryptocurrency theft and financial gain ESET Research releases latest APT Activity Report, highlighting cyber warfare of Russia-, China-, and Iran-aligned groups ESET Research joins global operation to disrupt the Grandoreiro banking trojan operating in Latin America and Spain Iran-linked OilRig attacks Israeli organizations with cloud service-powered downloaders, ESET Research discovers ESET Research: Official Python repository served cyberespionage backdoor, gathered 10,000+ downloads Predatory SpyLoan apps — loan sharks expand their range to Android, ESET Research finds ESET Research dives into the onboarding and scamming processes of Telekopye online fraudsters ESET Research: Android malware Kamran spying via news app on residents of the disputed Kashmir region ESET Research: Infamous IoT botnet Mozi taken down via a kill switch ESET APT Activity Report: China-aligned groups campaign against EU targets; prime target of Russia-aligned groups remains Ukraine ESET Research announces comprehensive report on Latin America’s threat landscape titled ‘Looking into TUT’s tomb: The universe of threats in LATAM’ ESET Research discovers Operation Jacana, targeting governmental entity in Guyana, likely by Chinese threat group ESET Research: North Korea-linked Lazarus impersonates Meta on LinkedIn to attack an aerospace company in Spain ESET and Calgary Flames Sign Multi-Year Partnership ESET Celebrates 10 Years in Montreal ESET Business Bundles Launch on Ingram Micro Cloud Marketplace
ESET Research: A deep dive into EDR killers - a cornerstone of modern ransomware operations
2026-03-19 · via RSS
  • EDR killers are a fundamental part of modern ransomware intrusions; affiliates prefer a short, reliable window to run encryptors rather than constantly modifying payloads.
  • Affiliates, not operators, pick the EDR killers; larger affiliate pools lead to greater tooling diversity.
  • EDR killers implement defense evasion techniques, while encryptors focus purely on encryption.
  • ESET strongly suspects that AI assists with the development of some EDR killers, and researchers provide a concrete example with the Warlock gang.
  • While BYOVD dominates, custom scripts, anti-rootkits, and driverless EDR killers are utilized as well.

BRATISLAVAMarch 19, 2026 — ESET Research releases its latest deep dive into the EDR killer ecosystem, disclosing how attackers abuse vulnerable drivers. ESET’s report presents telemetry-backed insights into the environment that move past the commonly seen driver-centric approach. It documents how affiliates, not operators, shape tooling diversity, and how codebases routinely reuse and swap drivers. EDR killers are a fundamental part of modern ransomware intrusions; as such, affiliates prefer a short, reliable window to run encryptors rather than constantly modifying payloads. Furthermore, ESET researchers assess that at least some recently observed EDR killers exhibit traits strongly suggestive of AI-assisted generation. Grounded in ESET telemetry and incident investigations, the research is based on the analysis and tracking of almost 90 EDR killers actively used in the wild. 

In recent years, EDR killers have become one of the most commonly seen tools in modern ransomware intrusions: an attacker acquires high privileges, deploys such a tool to disrupt protection, and only then launches the encryptor. Besides the omnipresent Bring Your Own Vulnerable Driver (BYOVD) technique, ESET also sees attackers frequently abusing legitimate anti-rootkit utilities or using driverless approaches to block the communication of endpoint detection and response (EDR) software or suspend it in place. Those abused tools are not just plentiful, but they also behave predictably and consistently, which is precisely why affiliates reach for them.

“The landscape this research unveils is massive, ranging from endless forking of proofs of concept to complex professional implementations. Focusing on commercial EDR killers – advertised on the dark net – allows us to gain a better understanding of their customer base and spot otherwise hidden affiliations. In-house-developed EDR killers offer insight into the inner workings of closed groups. Furthermore, vibe coding is making matters even more complicated,” says ESET researcher Jakub Souček, who investigated the EDR killers.

To successfully encrypt data, ransomware encryptors need to evade detection. Nowadays, a wide range of mature evasion techniques is available, ranging from packing and code virtualization to sophisticated injection. However, ESET rarely sees any of these implemented in encryptors. Instead, ransomware attackers opt for EDR killers to disrupt security solutions right before encryptor deployment.

At the same time, EDR killers often rely on legitimate, yet vulnerable, drivers, making defense significantly more difficult without risking disruption of legacy or enterprise software. The result is a class of tools that offers kernel-level impact with minimal development effort, making these tools disproportionately powerful, given their simplicity.

That is why ESET emphasizes that, while preventing vulnerable drivers from loading is a crucial step in the line of defense, it is not an easy one due to several existing bypass techniques. This highlights why one should not rely only on that, and aim to disrupt EDR killers before they even get a chance to load the driver. 

In fact, the simplest EDR killers don’t rely on vulnerable drivers or other advanced techniques. Instead, they abuse built-in administrative tools and commands. BYOVD techniques have become the hallmark of modern EDR killers: ubiquitous, reliable, and widely used. In a typical scenario, an attacker drops a legitimate, but vulnerable, driver onto the victim’s machine, installs the driver, and then runs malware that abuses the driver’s vulnerability. A smaller, but growing, class of EDR killers achieves its goals without touching the kernel at all. Instead of terminating EDR processes, these tools interfere with other critical features. 

Finally, AI can now be considered the latest weapon in the EDR killers’ arsenals. Determining whether AI directly assisted in producing a specific codebase is often practically impossible. There is no definitive forensic marker that reliably distinguishes AI-generated code from human-written code, especially when attackers post-process or obfuscate it. However, ESET researchers assess that at least some recently observed EDR killers exhibit traits strongly suggestive of AI-assisted generation.

A clear example appears in an EDR killer recently deployed by the Warlock ransomware gang. The tool contains a section of code that not only prints a list of possible fixes, a pattern typical for AI-generated boilerplates, but also, instead of exploiting a specific driver, implements a trial-and-error mechanism that cycles through several unrelated, commonly abused device names until it finds one that works. 

“A key observation is the division of labor in ransomware-as-a-service ecosystems. Operators typically supply the encryptor and supporting infrastructure, but EDR killer selection is left to affiliates. This means that the larger the affiliate pool, the more diverse the EDR killer tooling becomes,” explains Souček. “Defending against ransomware requires a fundamentally different mindset than defending against automated threats. Phishing emails, commodity malware, and exploit chains stop once detected and neutralized by security solutions; ransomware intrusions do not. They are interactive, human-driven operations, and intruders continually adapt to detections, tool failures, and environmental obstacles,” he adds.

For a more detailed analysis of EDR killers, check out the latest ESET Research blogpost “EDR killers explained: Beyond the drivers” on WeLiveSecurity.com. Make sure to follow ESET Research on Twitter (today known as X), BlueSky, and Mastodon for the latest news from ESET Research.

About ESET

ESET® provides cutting-edge cybersecurity to prevent attacks before they happen. By combining the power of AI and human expertise, ESET stays ahead of emerging global cyberthreats, both known and unknown—securing businesses, critical infrastructure, and individuals. Whether it’s endpoint, cloud, or mobile protection, our AI-native, cloud-first solutions and services remain highly effective and easy to use. ESET technology includes robust detection and response, ultra-secure encryption, and multifactor authentication. With 24/7 real-time defense and strong local support, we keep users safe and businesses running without interruption. The ever-evolving digital landscape demands a progressive approach to security: ESET is committed to world-class research and powerful threat intelligence, backed by R&D centers and a strong global partner network. For more information, visit www.eset.com or follow our social media, podcasts, and blogs.