Close Menu
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
What's Hot

Best sexting apps for secret chats in 2026

Your daily horoscope: June 17, 2026

‘Girls Like Girls’ favors nostalgia over the depth of a young queer awakening story

Facebook X (Twitter) Instagram
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
Facebook X (Twitter) Instagram
FYMOUS News
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
FYMOUS News
Home » Hackers reuse and attack the Ransom Hub edrkillshifter in Medusa, Baian
Celebrities

Hackers reuse and attack the Ransom Hub edrkillshifter in Medusa, Baian

By March 27, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

March 27, 2025Ravi LakshmananEndpoint Security/Ransomware

EdrkillShifter on Ransomhub

The new analysis reveals connections between Ransomhub affiliates and other ransomware groups such as Medusa, Bianlian and Play.

According to ESET, the connection is attributed to the use of custom tools designed to disable endpoint detection and response (EDR) software on compromised hosts. The EDR Killing Tool, known as Edrkillshifter, was first documented as used by Ransomhub actors in August 2024.

EdrkillShifter achieves its goals through a known tactic called Bring Your Own’s own Vulnerable Driver (BYOVD), which includes using legal but vulnerable drivers to terminate security solutions that protect endpoints.

Cybersecurity

The idea of ​​using such a tool is to ensure smooth execution of ransomware cryptographic devices without flagging them with security solutions.

“During the intrusion, the goal of affiliate marketing is to obtain admin or domain management privileges,” ESET researchers Jakub Souček and Jan Holman said in a report shared with Hacker News.

“Ransomware operators tend not to make large-scale updates of crypto companies as they introduce flaws that can cause problems and ultimately damage their reputation. As a result, security vendors detect crypto companies very well.

EdrkillShifter on Ransomhub

What is noteworthy here is that the bespoke tool developed by Ransomhub operators and provided to its affiliates – a rare phenomenon in itself – is used in other ransomware attacks related to Medusa, Bianlian and Play.

This aspect assumes special importance in light of the fact that both Play and Bian operate under a closed RAAS model. Their partnership is based on long-term mutual trust, as operators are not actively looking to hire new affiliates.

“The trusted members of Play and Bianlian have even worked together with newly emerging rivals like Ransomhub, and have since reused the tools they received from those rivals in their own attacks,” ESET theorized. “This is particularly interesting as these closed gangs usually employ a fairly consistent set of core tools during intrusions.”

All of these ransomware attacks are suspected to have been carried out by the same threat actor called Quadswitchers. Quad Switcher may be related to the closest play due to the similarity of the trademarks that are usually associated with play intrusions.

It has also been observed that EdrkillShifter is being used by another individual ransomware affiliate known as CosmicBeetle as part of three different Ransomhub and fake Lockbit attacks.

Cybersecurity

This development uses the BYOVD technique to deploy EDR killers to compromised systems amid a surge in ransomware attacks. Last year, ransomware gangs known as embargoes were discovered to neutralize security software using a program called MS4Killer. As this month, the Medusa ransomware crew is linked to a malicious driver called CodeNead Abyssworker.

“Threat actors need administrator privileges to deploy EDR killers, so ideally they should detect and mitigate their presence before reaching that point,” ESET said.

“Users, especially in corporate environments, should ensure that detection of potentially insecure applications is enabled, which will prevent the installation of vulnerable drivers.”

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleForgotten Playland: Beam’s flagship titles will be released on the Epic Games store: the ultimate multiplayer party game
Next Article Everything you need to know about the AI chatbot

Related Posts

Katie Holmes evokes ‘office siren’ at Max Mara Resort 2027 show

June 16, 2026

Duchess Kate wears Patrick McDowell bespoke with Order of the Garter

June 15, 2026

Melania Trump shows off her high fashion look in Dolce & Gabbana at UFC 250

June 15, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Best sexting apps for secret chats in 2026

Your daily horoscope: June 17, 2026

‘Girls Like Girls’ favors nostalgia over the depth of a young queer awakening story

This special Babbel offer gives you lifetime access to lessons created by linguists

Trending Posts

Deadmau5 adopts a cat he rescued by donating to an animal shelter

June 16, 2026

Ranking of all official World Cup songs

June 16, 2026

Jennifer Lopez needed to find herself again after divorce from Affleck

June 16, 2026

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to The FYMOUS, a modern digital media platform dedicated to celebrities, artists, influencers, brands, entertainment culture, and the growing TwinH ecosystem.

We bring audiences closer to the people, stories, trends, and collaborations shaping today’s culture. From exclusive celebrity news and music releases to influencer highlights, brand partnerships, and TwinH activations, The FYMOUS delivers engaging content designed for the next generation of digital audiences.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.