CardSpaceKiller
CardSpaceKiller is a commercial EDR killer used to disable endpoint detection and response software prior to ransomware deployment. ESET reporting places it within the growing underground market for EDR killers and describes such tools as a fundamental pre-encryption stage in modern ransomware intrusions, typically deployed after attackers obtain high privileges and before the encryptor runs. CardSpaceKiller has been observed in intrusions involving Akira, Medusa, Qilin, Crytox, and MedusaLocker, and is specifically noted as consistently appearing across Akira, Medusa, and MedusaLocker attacks. The tool is marketed on underground marketplaces as a service. CardSpaceKiller is consistently packed with the VX Crypt packer-as-a-service and uses anti-analysis and anti-detection techniques including call-by-hash API resolution and string obfuscation. Broader reporting on commercial EDR killers associated with CardSpaceKiller also notes common use of driver decoupling, encrypted embedded drivers or external encrypted payloads, code obfuscation, anti-VM behavior, and continuous repacking to hinder detection. No specific infection vector or standalone IOC values are provided in the source content.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Techniques & procedures
6 distinct techniques documented for this family, organized by ATT&CK tactic.
Privilege Escalation
1 technique
Privilege Escalation
Stealth
3 techniques
Stealth
Recent activity
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Commercial EDR killer used across multiple ransomware attacks to disable security products before encryption; it uses obfuscation such as call-by-hash resolution and string obfuscation.
An underground-market EDR killer service used to disable or interfere with security software.
Commercial EDR killer packed with VX Crypt; observed across multiple ransomware intrusions and capable of switching vulnerable drivers with minimal logic changes.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.