Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
54 EDR Killers Exploit Vulnerable Drivers to Evade Security

54 EDR Killers Exploit Vulnerable Drivers to Evade Security

Posted on March 19, 2026 By CWS

A recent investigation into endpoint detection and response (EDR) killers has unveiled that 54 of these tools exploit a technique known as bring your own vulnerable driver (BYOVD). This method involves manipulating 34 vulnerable drivers to bypass security systems. EDR killers have become a staple in ransomware attacks, providing a means for attackers to disable security measures before deploying file-encrypting malware, thus evading detection.

Understanding How EDR Killers Operate

Ransomware groups, particularly those utilizing ransomware-as-a-service (RaaS) models, frequently update their encryption tools, which can be time-consuming to keep undetectable. According to ESET researcher Jakub Souček, these encryptors are inherently conspicuous due to their need to modify numerous files rapidly. As a result, EDR killers are used to deactivate security features before launching the ransomware, keeping the process simple and efficient.

Most EDR killers exploit legitimate yet vulnerable drivers to obtain elevated privileges. Of the nearly 90 EDR killer tools identified by a Slovakian cybersecurity firm, over half employ the BYOVD tactic due to its reliability. The objective of such attacks is to attain kernel-mode privileges, allowing unrestricted access to system memory and hardware, as explained by Bitdefender.

Types of Threat Actors Utilizing EDR Killers

Threat actors leveraging BYOVD-based EDR killers are classified into three categories: closed ransomware groups like DeadLock, those modifying existing proof-of-concept codes such as SmilingKiller, and cybercriminals selling these tools on underground markets, including DemoKiller and ABYSSWORKER. These actors can disable security processes, tamper with kernel callbacks, and undermine endpoint protections, exploiting the trust in legitimate signed drivers.

Moreover, some script-based tools use built-in administrative commands to interfere with security processes, while others combine scripting with Windows Safe Mode to enhance their chances of disabling protection. However, this approach is risky due to the required system reboot, which is often unreliable in unknown environments.

Emerging Trends and Defensive Strategies

EDR killers are evolving, with new variants like driverless EDR killers blocking outbound traffic from EDR solutions, effectively putting them into a dormant state. Attackers focus more on sophisticated user-mode evasion techniques rather than making encryptors undetectable. This trend is particularly evident in commercial EDR killers, featuring advanced anti-analysis capabilities.

To counter these threats, it is crucial to block commonly exploited drivers from loading, as this can prevent EDR killer execution. However, as these tools are used in the final stages of an attack, attackers can easily switch to alternative tools if necessary. Thus, organizations must implement layered defenses and detection strategies to monitor and address threats throughout the attack lifecycle.

The persistence of EDR killers is attributed to their cost-effectiveness, reliability, and separation from the encryptors, making them ideal for both developers and affiliates seeking to disrupt security defenses before encryption, as noted by ESET.

The Hacker News Tags:BYOVD, cyber threats, Cybercriminals, Cybersecurity, defense mechanisms, EDR killers, endpoint detection, endpoint protection, kernel-mode privileges, layered security, Microsoft driver trust, Ransomware, ransomware-as-a-service, security evasion, vulnerable drivers

Post navigation

Previous Post: CISA Urges Security for Microsoft Intune After Breach
Next Post: 1stProtect Launches with $20M Funding for Security Innovation

Related Posts

TA446 Uses DarkSword Exploit in Spear-Phishing Campaign TA446 Uses DarkSword Exploit in Spear-Phishing Campaign The Hacker News
Confucius Hackers Hit Pakistan With New WooperStealer and Anondoor Malware Confucius Hackers Hit Pakistan With New WooperStealer and Anondoor Malware The Hacker News
CRESCENTHARVEST Campaign Targets Iranian Protest Allies CRESCENTHARVEST Campaign Targets Iranian Protest Allies The Hacker News
Tudou Guarantee Marketplace Halts Telegram Transactions After Processing Over  Billion Tudou Guarantee Marketplace Halts Telegram Transactions After Processing Over $12 Billion The Hacker News
Credential-Stealing Attack Hits SAP npm Packages Credential-Stealing Attack Hits SAP npm Packages The Hacker News
China-Linked APT31 Launches Stealthy Cyberattacks on Russian IT Using Cloud Services China-Linked APT31 Launches Stealthy Cyberattacks on Russian IT Using Cloud Services The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • OpenAI Delays Astra AI Model to Address Cybersecurity Risks
  • UNC6671 Cyber Threat Intensifies with Vishing Attacks
  • ChainDrop Worm Targets npm Packages for Credential Theft
  • macOS Malware Steals Crypto via ClickFix Attacks
  • Malware Exploits Windows Hello Keys to Access Entra ID

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • OpenAI Delays Astra AI Model to Address Cybersecurity Risks
  • UNC6671 Cyber Threat Intensifies with Vishing Attacks
  • ChainDrop Worm Targets npm Packages for Credential Theft
  • macOS Malware Steals Crypto via ClickFix Attacks
  • Malware Exploits Windows Hello Keys to Access Entra ID

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark