Tag: edr
-
Ransomware Groups Increasingly Deploy EDR Kill Techniques
Halcyon’s latest quarterly ransomware report showed that while ransomware attacks are declining, obfuscation techniques are getting harder to fight against First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ransomware-q2-2026-edr-kill/
-
New TriBack Loader Evades EDR Using Signed Binaries and Win32 Callback APIs
A new shellcode loader, dubbed “TriBack Loader,” to a China-nexus intrusion cluster tracked as JadeProx, with the malware explicitly engineered to evade modern EDR by abusing signed binaries and uncommon Win32 callback APIs. Across at least four observed variants, the loader underpins simultaneous espionage campaigns in South-East Asia and Latin America, including targeting of a…
-
4 ways to secure local developer IDEs and tools without sacrificing velocity
Attention shifts from EDR to Agentic Endpoint Security to close visibility gaps that AI can exploit. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/spons/4-ways-to-secure-local-developer-ides-and-tools-without-sacrificing-velocit/825550/
-
Microsoft Defender XDR Blind Spot Lets Public C2 Traffic Evade Detection Queries
Microsoft Defender XDR users may inadvertently overlook command-and-control (C2) traffic when searching for Internet-bound connections due to a specific behavior in how IP addresses are classified. This issue arises from Kusto Query Language (KQL) detections that depend solely on filtering by RemoteIPType == >>Public<< in the DeviceNetworkEvents table. As a result, traffic destined for public…
-
Hackers Use Cruciferra Crypter to Disable EDR and Deploy XWorm, Remcos, and AsyncRAT
Hackers are abusing the Cruciferra crypter-as-a-service to systematically turn off endpoint detection and response (EDR) tools and stealthily deploy XWorm, Remcos, AsyncRAT, and other commodity malware in email-driven campaigns targeting multiple sectors worldwide. By combining BYOVD-based driver abuse, indirect syscalls and a polymorphic encryption engine with more than 90 mix-and-match crypto routines, Cruciferra has rapidly…
-
How agentic endpoint security shuts down IDE-based supply chain attacks
Attention shifts from EDR to Agentic Endpoint Security to close visibility gaps that AI can exploit. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/spons/how-agentic-endpoint-security-shuts-down-ide-based-supply-chain-attacks/825550/
-
Furtex Linux Toolkit Uses io_uring and eBPF to Bypass EDR and Falco Detection
A newly published Linux toolkit named Furtex showcases a wide range of concepts related to post-exploitation, persistence, data access, and monitoring evasion. It is built around io_uring, eBPF, BPF maps, and raw system calls. The project includes over 100 tools organized into modules that cover asynchronous I/O operations, BPF inspection and manipulation, EDR evasion techniques,…
-
ClickFix’s Mushrooming Ecosystem Demands New Defense Tactics
The attack vector is available for rent at scale, and evades AV and EDR, leaving YARA analysis as the best detection option. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/clickfixs-ecosystem-demands-new-defense
-
SindriKit 1.3.0 Abuses Call Stack Spoofing to Bypass EDR Detection
SindriKit 1.3.0 introduces a significant advancement in evading Endpoint Detection and Response (EDR) systems by exploiting dynamic call stack spoofing. This method defeats telemetry that inspects kernel-transition call chains, going beyond just user-mode hooks. Previously, SindriKit 1.2.0 had already separated syscall invocations via indirect syscalls, redirecting to legitimate syscall return instructions in ntdll.dll to evade…
-
SindriKit 1.3.0 Abuses Call Stack Spoofing to Bypass EDR Detection
SindriKit 1.3.0 introduces a significant advancement in evading Endpoint Detection and Response (EDR) systems by exploiting dynamic call stack spoofing. This method defeats telemetry that inspects kernel-transition call chains, going beyond just user-mode hooks. Previously, SindriKit 1.2.0 had already separated syscall invocations via indirect syscalls, redirecting to legitimate syscall return instructions in ntdll.dll to evade…
-
Ransomware-Gruppe schaltet Sicherheitssoftware mit EDR-Killer aus
Die Betreiber der Ransomware-Gruppe Gentlemen stellen ihren Partnern nicht nur Verschlüsselungswerkzeuge zur Verfügung, sondern entwickeln auch eigene Programme zur gezielten Umgehung und Abschaltung von Sicherheitssoftware. Besonders betroffen sind die in Netzwerken oft eingesetzten ‘Endpoint-Detection and Response”-Lösungen. Das zeigt eine aktuelle Analyse des IT-Sicherheitsherstellers ESET. Demnach pflegt die Gruppe ein eigenes Portfolio sogenannter EDR-Killer und integriert…
-
AI-Powered Reverse Engineering Turns EDR Rule Analysis Into Automated Evasion Workflow
LLMs are reshaping endpoint security research by turning what used to be slow, manual reverse engineering into an automated, repeatable evasion workflow. Recent hands-on experiments with advanced models driving disassembly and local analysis show that a compact harness LLM plus disassembler, a shared state file, and a loop can recover EDR artifacts, decrypt local signature…
-
Hackers Use Vulnerable Windows Drivers to Kill EDR in Ransomware Attacks
Hackers increasingly rely on vulnerable, legitimately signed Windows drivers to neutralize endpoint defenses, turning defense evasion into a decisive phase of modern ransomware attacks. Over the past three years the Bring Your Own Vulnerable Driver (BYOVD) technique has migrated from research proof-of-concept into a commoditized, routinely deployed capability in ransomware-as-a-service toolkits. By abusing signed kernel…
-
macOS Flaw Lets Standard Users Disable EDR and MDM
macos-xpc-flaw-disable-edr-mdm-standard-user-xm-cyber First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/macos-xpc-flaw-disable-edr-mdm/
-
GentleKiller Framework Disables Victims’ Security Software
ESET details GentleKiller, the EDR-killer framework the Gentlemen ransomware gang gives affiliates First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/gentlekiller-gentlemen-ransomware/
-
âš¡ Weekly Recap: Browser Bugs, EDR Killers, TV Botnet, OpenBSD Flaw, Android Trojan, and More
It’s Monday again.This week’s threat list looks painfully familiar: abused integrations, fake tools, poisoned websites, ransomware crews trying to shut down security tools, and mobile malware asking for way too much control.The annoying part is how little of this feels new. Weak credentials, sketchy downloads, browser extensions with too much access, and WordPress sites are…
-
LACUNA Chain Ghost Frames Technique Bypasses EDR Call-Stack Detection
The LACUNA Chain’s “Ghost Frames” technique introduces a new method for manipulating call stacks that effectively bypasses modern Endpoint Detection and Response (EDR) systems, which rely on kernel-level stack inspection. This marks a significant advancement in post-exploitation tactics. Security researcher Mohamed Alzhrani has described this technique as a continuation of previous research known as “HookChain,”…
-
LACUNA Chain Ghost Frames Technique Bypasses EDR Call-Stack Detection
The LACUNA Chain’s “Ghost Frames” technique introduces a new method for manipulating call stacks that effectively bypasses modern Endpoint Detection and Response (EDR) systems, which rely on kernel-level stack inspection. This marks a significant advancement in post-exploitation tactics. Security researcher Mohamed Alzhrani has described this technique as a continuation of previous research known as “HookChain,”…
-
Security Affairs newsletter Round 582 by Pierluigi Paganini INTERNATIONAL EDITION
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. Inside GentleKiller: The EDR-Killer Powering The Gentlemen FortiBleed Exposes Global Credential-Spraying Operation CISA Warns of Active…
-
Inside GentleKiller: The EDR-Killer Powering The Gentlemen
The Gentlemen equips affiliates with a centralized EDR-killer suite, rapidly weaponizing BYOVD exploits to disable security tools before ransomware attacks. ESET published a detailed breakdown of The Gentlemen’s technical infrastructure on June 18, the result of months of incident-level investigation corroborated by the group’s own internal data leak from May 2026. Since emerging in late…
-
Gar nicht Gentlemen-like: Hackergruppe schaltet Sicherheitssoftware mit “EDR-Killer-Framework” aus
Tags: edrESET Research veröffentlicht die Ergebnisse einer monatelangen Untersuchung der von der RaaS-Bande ‘Gentlemen” betriebenen EDR-Killer-Suite. First seen on welivesecurity.com Jump to article: www.welivesecurity.com/de/eset-research/gar-nicht-gentlemen-like-hackergruppe-schaltet-sicherheitssoftware-mit-edr-killer-framework-aus/
-
Gentlemen-Ransomware hebelt EDR-Schutz aus
Die Erpressergruppe Gentlemen nutzt ein Arsenal an EDR-Killern wie GentleKiller, um Antiviren-Programme gezielt auszuschalten und Daten zu verschlüsseln. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/edr-schutz-gentlemen-ransomware
-
The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes
The Gentlemen ransomware-as-a-service (RaaS) operation is actively developing and maintaining a suite of endpoint detection and response (EDR) killers that it hands out to affiliates for impairing system defenses before deploying the encryptor.This mature portfolio of EDR-terminating tools is centered around a framework that’s known as GentleKiller.”They also incorporate third-party or First seen on thehackernews.com…
-
Gentlemen ransomware uses multiple EDR killers to disable defenses
The Gentlemen ransomware-as-a-service (RaaS) is actively developing and maintaining a suite of endpoint detection and response (EDR) killers to help affiliates evade detection in attacks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/gentlemen-ransomware-uses-multiple-edr-killers-to-disable-defenses/
-
The Gentlemen Ransomware Gang Standardizes EDR Killing
Eset Links Group’s Growth to Integrated Endpoint-Killing Tools. Eset researchers say the rapidly growing Gentlemen ransomware operation differentiates itself by supplying affiliates with a standardized EDR-killer suite that disables security tools, quickly incorporates newly disclosed vulnerable drivers and helps scale attacks across multiple regions worldwide. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/gentlemen-ransomware-gang-standardizes-edr-killing-a-32007
-
Hackers Abuse Compromised WordPress Sites to Deliver GULoader Through EtherHiding Chain
In April 2026, incident responders traced a sophisticated intrusion that abused compromised WordPress sites to deliver GULoader via an EtherHiding → ClickFix → UNC-chain. The real-world ClickFix incident produced convergent evidence from an ANY.RUN sandbox detonation and live EDR telemetry, revealing a complete, user-initiated attack path from a WordPress mu-plugin backdoor to a blocked rundll32.exe…
-
Microsoft changes how Defender for Endpoint EDR updates are delivered on Windows
Microsoft will distribute Defender for Endpoint EDR updates through Microsoft Update, enabling EDR security improvements to be released independently of monthly Windows … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/08/microsoft-defender-for-endpoint-edr-updates/
-
EDRChoker Tool Abuses Windows QoS Policies to Disrupt Endpoint Security Tools
A newly disclosed red-team tool dubbed “EDRChoker” is drawing attention across the cybersecurity community for its novel approach to disrupting Endpoint Detection and Response (EDR) visibility by abusing Windows Policy-based Quality of Service (quality of service). Unlike traditional EDR evasion techniques that rely on firewall manipulation or Windows Filtering Platform (WFP) rule injection, EDRChoker operates…
-
Payouts King Ransomware Bypasses EDR via Obfuscation and Direct Syscalls
Payouts King ransomware has emerged as a notable post-BlackBasta threat, leveraging advanced obfuscation and direct system calls to evade endpoint detection and response (EDR) solutions. Threat activity observed in early 2026 shows strong overlaps with historical BlackBasta tradecraft, particularly the use of spam bombing combined with phishing and vishing. In these campaigns, attackers overwhelm victims…

