EDRKillShifter is an EDR-disruption / EDR-killer tool developed and maintained by the RansomHub ransomware-as-a-service operation and offered to affiliates through its affiliate panel. It was first introduced to affiliates in May 2024 and was first seen deployed in August 2024. Multiple reports describe it as a bring-your-own-vulnerable-driver (BYOVD) utility for Windows that loads a legitimate but vulnerable kernel driver to gain kernel-level capabilities and terminate security products before ransomware deployment. Sophos characterized it as a loader executable that requires a unique 64-character command-line password to run; with the correct password it decrypts an embedded BIN resource, writes and deletes a temporary Config.ini file, and executes additional stages in memory. The second stage uses self-modifying code, and analyzed final payloads were Go-based and obfuscated. Payloads embedded a vulnerable driver in the .data section, dropped the driver to %AppData%\Local\Temp under a random filename, created and started a service for it, then entered a continuous loop enumerating and terminating targeted processes. Observed variants abused vulnerable drivers including RentDrv2 and ThreatFireMonitor, and reporting also states EDRKillShifter used at least two different vulnerable drivers overall. Sophos assessed that portions of public GitHub proof-of-concept BYOVD exploits were likely copied and ported to Go. Reported targets include products from Sophos, Microsoft Defender, Bitdefender, Cylance, ESET, F-Secure, Fortinet, Kaspersky, McAfee, SentinelOne, Symantec, Trend Micro, HitmanPro, and Webroot. ESET identified EDRKillShifter as a custom tool tied to RansomHub and linked its use beyond RansomHub-only cases, including affiliate activity associated with Play, Medusa, and BianLian; later reporting says updated versions were repurposed by Medusa, BianLian, and Play, and Water Bakunawa was also reported using it. Sophos detects it as Troj/KillAV-KG. High-confidence sample identifiers mentioned in the content include SHA256 451f5aa55eb207e73c5ca53d249b95911d3fad6fe32eee78c58947761336cc60 and d0f9eae1776a98c77a6c6d66a3fd32cee7ee6148a7276bc899c1a1376865d9b0, as well as SHA-1 BF84712C5314DF2AA851B8D4356EA51A9AD50257 and 77DAF77D9D2A08CC22981C004689B870F74544B5 linked by ESET to affiliate activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
BadRentdrv2 ... rentdrv2ドライバの脆弱性(CVE-2023-44976)を悪用するBYOVD PoC。x32/x64両対応で、EDR/AVプロセスをPID指定で終了可能。RansomHub等のEDRKillShifterでも悪用が確認されている
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
For comparison, ESET notes that RansomHub , another prominent RaaS operation, built a single in-house EDR killer ( EDRKillShifter ) for affiliate use via its affiliate panel.
RansomHub’s EDR killer, named EDRKillShifter by Sophos, is a custom tool developed and maintained by the operator.
Water Bakunawa uses EDRKillShifter to evade detection and disrupt security monitoring processes.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
Some samples, like those documented in early EDRKillShifter research, require a 64-character password supplied on the command line before they will execute, which gates the binary against sandbox analysis.
All samples require a unique 64-character password passed to the command line. If the password is wrong (or not provided), it won’t execute.
The loader unpacks its real payload in memory using self-modifying code.
The original filename is Loader.exe and its product name is ARK-Game. (Some members of the research team speculated that the threat actor tries to masquerade the final payload as a popular computer game named ARK: Survival Evolved.)
It also copies that data into a new file named Config.ini and writes that file to the same filesystem location where the binary was executed... The malware then deletes the config.ini file
When run with the correct password, the executable decrypts an embedded resource named BIN and executes it in memory.
RansomHub’s builder adds an additional layer of protection to its encryptors, a 64-character password, without which the encryptor does not work.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A kernel-mode EDR killer that disables endpoint agents, with some samples protected by a command-line password to hinder sandbox analysis. The content describes it as part of the same operational pattern leading to ransomware deployment.
An in-house EDR killer associated with the RansomHub RaaS operation, mentioned for comparison with Gentlemen’s broader tooling portfolio.
An in-house EDR killer developed by RansomHub and offered to affiliates, mentioned as a comparison point to Gentlemen’s broader EDR-killer portfolio.
EDR killer designed to disable endpoint detection and response tools; noted for password-protecting key code sections.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.