EDR killers are central to current ransomware intrusions: perpetrators prefer short, secure windows to encrypt data. They are chosen by members, not by operators, and increase the diversity of tools. They use evasion techniques, sometimes supported by AI, as in the case of the Warlock group; mainly BYOVD tools are used, but also custom scripts, anti-rootkits and driverless EDR killers
ESET Research releases the latest analysis of the “EDR killers” ecosystem, revealing how attackers exploit vulnerable drivers. ESET's report presents telemetry-based insights into this environment that go beyond the common driver-centric approach. The document illustrates how affiliates, not operators, determine the diversity of tools, and how source codes regularly reuse and replace drivers. EDR killers are central to modern ransomware intrusions, and affiliates prefer a short window to run encryption programs rather than constantly modifying payloads. Furthermore, ESET researchers believe that at least some recently observed EDR killers exhibit characteristics that suggest AI-assisted generation. Based on ESET telemetry and incident investigations, the research is based on the analysis and monitoring of almost 90 active EDR killers in circulation.
In recent years, “EDR killers” have become one of the most popular tools in modern ransomware intrusions: an attacker gains elevated privileges, employs one of these tools to bypass protection systems, and only then launches the encryption program. In addition to the ubiquitous Bring Your Own Vulnerable Driver (BYOVD) technique, ESET notes that attackers frequently abuse legitimate anti-rootkit utilities or use driverless approaches to block endpoint detection and response (EDR) software communication or pause it. These compromised tools are not only numerous, but also behave predictably and consistently, which is why they are so widely used.
"The context outlined by the research is vast and ranges from infinite ramifications of proof of concept to complex professional implementations. Focusing on commercially available EDR killers advertised on the dark web allows us to better understand their user base and identify otherwise hidden affiliations. Internally developed EDR killers offer in-depth insight into the inner workings of restricted communities. Furthermore, vibe coding is making things even more complicated", says Jakub Souček, researcher at ESET, who analyzed the EDR killers.
In order to successfully encrypt data, ransomware programs must evade detection. Today, there is a wide range of established circumvention techniques, ranging from packing and code virtualization to sophisticated injection techniques. However, ESET rarely detects the implementation of such techniques in encryption programs. Ransomware attackers instead opt for “EDR killers” to compromise security measures before running the encryption program.
At the same time, EDR killers often rely on legitimate, but vulnerable drivers, making defense significantly more difficult without risking compromising legacy or enterprise software. The result is a class of tools that delivers kernel-level impact with minimal development effort, making these tools disproportionately powerful given their simplicity.
That's why ESET emphasizes that, while preventing vulnerable drivers from loading is a crucial step in the line of defense, it is not an easy task due to the various existing bypass techniques and it would be useful to aim to neutralize EDR killers before they even have the chance to download the driver.
In reality, the simplest tools for evading EDRs do not rely on vulnerable drivers or other advanced techniques. Instead, they take advantage of built-in administrative tools and commands. BYOVD techniques have become the hallmark of modern EDR evasion tools: ubiquitous, reliable, and widely used. In a typical scenario, an attacker places a legitimate, but vulnerable, driver on the victim's computer, installs it, and then executes malware that exploits the driver's vulnerability. A smaller but growing class of EDR killers achieve their goals without touching the kernel at all. Instead of terminating EDR processes, these tools interfere with other critical functionality.
Finally, AI can be considered the latest weapon in the arsenal of EDR killers. Determining whether AI directly assisted in the production of specific code is often virtually impossible. There is no definitive forensic indicator that reliably distinguishes AI-generated code from human-written code, especially when attackers post-process or obfuscate it. However, ESET researchers believe that at least some recently observed EDR killers exhibit characteristics that strongly suggest AI-assisted generation.
A clear example is provided by an EDR killer recently distributed by the Warlock gang. The tool contains a section of code that not only prints a list of possible fixes, a pattern typical of AI-generated boilerplates, but instead of leveraging a specific driver, it implements a trial-and-error mechanism that cycles through several unrelated and commonly fraud device names until it finds one that works.
«A key aspect is the division of labor in ransomware-as-a-service ecosystems. The authors of these attacks usually provide the encryption program and supporting infrastructure, but the choice of tools to bypass EDR systems is left to the affiliates. This means that the larger the pool of affiliates, the more diverse the tools used to circumvent EDR systems become,” explains Souček. «Defending against ransomware requires a fundamentally different mindset than defending against automated threats. Phishing emails, generic malware and exploit chains stop once detected and neutralized by security solutions; ransomware intrusions do not. These are interactive, human-driven operations, and intruders continually adapt to detections, instrument malfunctions and environmental obstacles,” he concludes.






