Multiple ransomware groups have begun leveraging a new packer-as-a-service platform called Shanya Crypter to bypass endpoint detection and response (EDR) solutions. Shanya Crypter utilizes kernel driver abuse to terminate EDR processes, making ransomware payloads significantly harder to detect and stop. The service provides custom wrappers for each customer, employing unique encryption algorithms and memory injection techniques that avoid writing payloads to disk, further complicating detection by traditional security tools. Notable ransomware groups such as Medusa, Qilin, Crytox, and Akira have been confirmed to use Shanya, with attacks observed in regions including Tunisia, the UAE, Costa Rica, Nigeria, and Pakistan.
The emergence of Shanya Crypter marks a significant evolution in ransomware delivery tactics, as it enables threat actors to deploy EDR-killing payloads with greater stealth and efficiency. Security researchers have highlighted the technical sophistication of Shanya, including its use of non-standard module loading and the ability to generate unique stubs for each customer. This development underscores the ongoing arms race between ransomware operators and defenders, with attackers increasingly turning to advanced packing and obfuscation services to maintain the effectiveness of their campaigns.

Get the actors, campaigns, and ATT&CK mapping behind it.
4 events from the most recent confirmed update back to the earliest known activity.
Sophos publicly released technical details on how Shanya works, including its use of memory-mapped legitimate DLLs, anti-debugging measures, DLL side-loading tradecraft, and the driver-based EDR killer chain. The report also provided indicators of compromise to help defenders detect related activity.
By early December 2025, researchers reported that ransomware groups including Medusa, Qilin, Crytox, and Akira were using Shanya-packed DLLs in side-loading attacks to deploy payloads that disable endpoint detection and response products. The attacks used legitimate Windows components and abused drivers such as signed ThrottleStop.sys and unsigned hlpdrv.sys to gain privileges and interfere with security software.
Sophos observed Shanya being used not only by ransomware operators but also in other malware activity, including ClickFix campaigns delivering CastleRAT. This showed the service was being adopted across multiple types of criminal operations.
Shanya emerged in late 2024 as a packer-as-a-service platform used to obfuscate malware payloads with custom encryption, compression, and anti-analysis techniques. It was designed to make malicious files harder for security tools and analysts to detect and inspect.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.