RealBlindingEDR is an open-source Windows endpoint-security evasion tool designed to disable or impair endpoint detection and response (EDR) products. It operates at kernel level, targeting security-product callbacks and hooks to suppress protection capabilities. Modified variants have used the vulnerable Echo.ac anti-cheat driver, tracked as CVE-2023-38817, to obtain kernel-level access, remove EDR-related kernel routines, and elevate privileges through token theft. Observed variants have also attempted to terminate or crash endpoint-security processes.
Customized RealBlindingEDR variants have been used by the Crypto24 ransomware operation against enterprise victims in financial services, manufacturing, entertainment, and technology across Asia, Europe, and the United States. A variant used by Crypto24 identifies security products through driver metadata and disables callbacks for a hardcoded list of numerous vendors. Modified samples were also used in Operation Crimson Palace, a Chinese state-directed cyberespionage campaign targeting government and public-service organizations in Southeast Asia. The tool is deployed after compromise to reduce endpoint visibility and facilitate follow-on activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In January 2024, Sophos MDR observed the actors deploying two slightly modified samples of RealBlindingEDR, an open-source tool designed to “blind” (or kill) malware protection and endpoint detection and response (EDR) solutions.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
The binaries exploit a vulnerability in an anti-cheat tool for Minecraft called Echo.ac (CVE-2023-38817) ... to remove kernel routines used by a number of different EDR products, which allows the actors to escalate their privileges through token theft.
copying the application’s dynamic linking library (DLL) to a web documents folder and disguising it as a PDF... a malicious DLL masquerading as an .ini file... TattleTale was deployed as the file r2.exe
The attackers also took measures to disable endpoint protection software or evade detection when it could not be disabled.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An open-source anti-EDR utility customized by the Crypto24 operators to impair endpoint defenses. The observed variant identifies security-product drivers by company metadata and removes callbacks; it may use unknown vulnerable drivers for evasion.
An open-source EDR killer used to disable or blind security products by exploiting a vulnerable driver, removing kernel callbacks, escalating privileges, and terminating security processes such as SophosFileScanner.exe.
An open-source EDR killer used to disable or crash security products. In this campaign it loaded a vulnerable driver, removed kernel callbacks used by EDR products, killed SophosFileScanner.exe, and in one variant attempted to crash EDR processes via Image File Execution Options registry abuse.
Custom defense-evasion tool used to impair endpoint protections by targeting core Microsoft security drivers (e.g., WdFilter.sys, MpKslDrv.sys, mpsdrv.sys, WdNisDrv.sys) and removing callbacks from drivers associated with multiple security vendors (e.g., Gen Digital, Kaspersky, Sophos, Trend Micro, Malwarebytes, Bitdefender, McAfee, Fortinet, Sentinel).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.