A cybercrime group associated with the RansomHub ransomware has been found deploying a new tool aimed at disabling endpoint detection and response (EDR) software on compromised systems. This tool is now part of a growing arsenal of similar utilities, including AuKill (also known as AvNeutralizer) and Terminator.
The cybersecurity firm Sophos has named this new utility EDRKillShifter after identifying it during an unsuccessful ransomware attempt in May 2024.
“EDRKillShifter acts as a ‘loader’ executable—a mechanism for delivering a legitimate but exploitable driver, commonly referred to as a ‘bring your own vulnerable driver’ (BYOVD) tool,” explained security researcher Andreas Klopsch. “The tool can deploy various driver payloads depending on the threat actor’s objectives.”
RansomHub, which is believed to be a rebranding of the Knight ransomware, emerged in February 2024. The group has been exploiting known security vulnerabilities to gain initial access and deploy legitimate remote desktop software like Atera and Splashtop for persistent control.
In a recent disclosure, Microsoft noted that the notorious cybercrime group Scattered Spider has integrated ransomware strains such as RansomHub and Qilin into its operations.
The EDRKillShifter executable operates via command-line input, using a password string to decrypt and execute an embedded resource called BIN directly in memory. This BIN resource then launches a Go-based, obfuscated final payload that exploits various legitimate drivers to gain elevated privileges and neutralize EDR defenses.
“The binary’s language settings indicate that it was compiled on a system with Russian localization,” Klopsch added. “All the extracted EDR-killing tools contain a vulnerable driver embedded within the .data section.”
To counter this threat, experts recommend keeping systems updated, enabling tamper protection in EDR software, and maintaining strong security practices for Windows roles.
“This attack requires the attacker to either escalate their privileges or gain administrator rights,” Klopsch noted. “Maintaining a clear separation between user and admin privileges can make it harder for attackers to load malicious drivers.”
Meanwhile, cybersecurity researchers have observed attackers deploying a new stealthy malware called SbaProxy. This malware modifies legitimate antivirus binaries from BitDefender and Malwarebytes, re-signing them with fake certificates to create proxy connections through a command-and-control (C2) server.
SbaProxy is designed to establish a proxy connection that routes traffic between the client and the target through the C2 server and the infected machine. It only supports TCP connections.
“AT&T’s LevelBlue Labs emphasized the significant impact of this threat, noting that it can be used to create proxy services for malicious purposes, which could then be sold for financial gain,” the firm stated. “This tool, available in formats such as DLLs, EXEs, and PowerShell scripts, is particularly difficult to detect due to its sophisticated design and the use of legitimate-looking files.”



