Cybercriminals Redeploy RansomHub’s EDRKillShifter in Medusa, BianLian, and Play Intrusions

Recent research has unveiled links between associates of RansomHub and additional ransomware factions such as Medusa, BianLian, and Play.

Recent research has unveiled links between associates of RansomHub and additional ransomware factions such as Medusa, BianLian, and Play. These ties are established through a specialized utility created to deactivate endpoint detection and response (EDR) applications on infiltrated systems, as detailed by ESET. Known as EDRKillShifter, this tool for neutralizing EDR software was initially observed in action by operators associated with RansomHub

About Author

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.