×
ItalianoEnglish
Set as default language

Grandangolo Communications

  • Home
  • Company
  • Services
    • Public Relation
    • Digital PR
    • Marketing
    • Lead Generation
    • Events
  • Best Practice
  • Customer Press Room
  • Contacts
  • Languages
  • Home
  • Customer Press Room
  • Eset
  • ESET Research: In-depth analysis of “EDR killers” – cornerstone of modern ransomware operations

Customer Press Room

ESET Research: In-depth analysis of “EDR killers” – cornerstone of modern ransomware operations

by Grandangolo Communications / Thursday, 19 March 2026 / Published in Eset

EDR killers are central to current ransomware intrusions: perpetrators prefer short, secure windows to encrypt data. They are chosen by members, not by operators, and increase the diversity of tools. They use evasion techniques, sometimes supported by AI, as in the case of the Warlock group; mainly BYOVD tools are used, but also custom scripts, anti-rootkits and driverless EDR killers

ESET Research releases the latest analysis of the “EDR killers” ecosystem, revealing how attackers exploit vulnerable drivers. ESET's report presents telemetry-based insights into this environment that go beyond the common driver-centric approach. The document illustrates how affiliates, not operators, determine the diversity of tools, and how source codes regularly reuse and replace drivers. EDR killers are central to modern ransomware intrusions, and affiliates prefer a short window to run encryption programs rather than constantly modifying payloads. Furthermore, ESET researchers believe that at least some recently observed EDR killers exhibit characteristics that suggest AI-assisted generation. Based on ESET telemetry and incident investigations, the research is based on the analysis and monitoring of almost 90 active EDR killers in circulation.

In recent years, “EDR killers” have become one of the most popular tools in modern ransomware intrusions: an attacker gains elevated privileges, employs one of these tools to bypass protection systems, and only then launches the encryption program. In addition to the ubiquitous Bring Your Own Vulnerable Driver (BYOVD) technique, ESET notes that attackers frequently abuse legitimate anti-rootkit utilities or use driverless approaches to block endpoint detection and response (EDR) software communication or pause it. These compromised tools are not only numerous, but also behave predictably and consistently, which is why they are so widely used.

"The context outlined by the research is vast and ranges from infinite ramifications of proof of concept to complex professional implementations. Focusing on commercially available EDR killers advertised on the dark web allows us to better understand their user base and identify otherwise hidden affiliations. Internally developed EDR killers offer in-depth insight into the inner workings of restricted communities. Furthermore, vibe coding is making things even more complicated", says Jakub Souček, researcher at ESET, who analyzed the EDR killers.

In order to successfully encrypt data, ransomware programs must evade detection. Today, there is a wide range of established circumvention techniques, ranging from packing and code virtualization to sophisticated injection techniques. However, ESET rarely detects the implementation of such techniques in encryption programs. Ransomware attackers instead opt for “EDR killers” to compromise security measures before running the encryption program.

At the same time, EDR killers often rely on legitimate, but vulnerable drivers, making defense significantly more difficult without risking compromising legacy or enterprise software. The result is a class of tools that delivers kernel-level impact with minimal development effort, making these tools disproportionately powerful given their simplicity.

That's why ESET emphasizes that, while preventing vulnerable drivers from loading is a crucial step in the line of defense, it is not an easy task due to the various existing bypass techniques and it would be useful to aim to neutralize EDR killers before they even have the chance to download the driver.

In reality, the simplest tools for evading EDRs do not rely on vulnerable drivers or other advanced techniques. Instead, they take advantage of built-in administrative tools and commands. BYOVD techniques have become the hallmark of modern EDR evasion tools: ubiquitous, reliable, and widely used. In a typical scenario, an attacker places a legitimate, but vulnerable, driver on the victim's computer, installs it, and then executes malware that exploits the driver's vulnerability. A smaller but growing class of EDR killers achieve their goals without touching the kernel at all. Instead of terminating EDR processes, these tools interfere with other critical functionality.

Finally, AI can be considered the latest weapon in the arsenal of EDR killers. Determining whether AI directly assisted in the production of specific code is often virtually impossible. There is no definitive forensic indicator that reliably distinguishes AI-generated code from human-written code, especially when attackers post-process or obfuscate it. However, ESET researchers believe that at least some recently observed EDR killers exhibit characteristics that strongly suggest AI-assisted generation.

A clear example is provided by an EDR killer recently distributed by the Warlock gang. The tool contains a section of code that not only prints a list of possible fixes, a pattern typical of AI-generated boilerplates, but instead of leveraging a specific driver, it implements a trial-and-error mechanism that cycles through several unrelated and commonly fraud device names until it finds one that works.

«A key aspect is the division of labor in ransomware-as-a-service ecosystems. The authors of these attacks usually provide the encryption program and supporting infrastructure, but the choice of tools to bypass EDR systems is left to the affiliates. This means that the larger the pool of affiliates, the more diverse the tools used to circumvent EDR systems become,” explains Souček. «Defending against ransomware requires a fundamentally different mindset than defending against automated threats. Phishing emails, generic malware and exploit chains stop once detected and neutralized by security solutions; ransomware intrusions do not. These are interactive, human-driven operations, and intruders continually adapt to detections, instrument malfunctions and environmental obstacles,” he concludes.

Tagged under: Eset

About Grandangolo Communications

What you can read next

ESET: Gamaredon and Turla, groups linked to the Russian Federal Security Service, collaborate to target high-profile entities in Ukraine
ESET Research investigates the Gentlemen ransomware author group and its defense evasion tools
ESET Research: Toolkit used by ransomware group Embargo discovered that disables security solutions

Customer Press Room

  • ESET Research: FamousSparrow steps up operations in Latin America and hits governments with new backdoor

    The pro-Chinese APT group concentrates its activities...
  • ESET's ultra-fast, high-accuracy threat detection scanner, now available in AWS Marketplace

    The ESET PRIVATE Scanning Solutions suite is available...
  • Arrow Electronics signs distribution agreement with Usercentrics

    Arrow Electronics, a global supplier of technology...
  • Acronis names Denis Cassinerio Vice President South Europe CEE

    In the new role the manager will continue the...
  • SentinelOne enhances Wayfinder's Frontier AI services by integrating OpenAI's Daybreak models

    Advanced cybersecurity services expanded with...

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • May 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019
  • December 2018

Categories

  • A10
  • Abstract
  • abstract
  • Acronis
  • Ally Consulting
  • Arrow
  • Arrow Electronics
  • Axiante
  • Babel
  • Computer Center
  • Cohesity
  • Italy Cloud Consortium
  • Consys
  • D-Link
  • Eset
  • G.B. Service
  • Habble
  • HiSolution
  • HYCU
  • Icos
  • Imprivate
  • Information Tecnology
  • Innovaway
  • Ivanti
  • Link11
  • MobileIron
  • Netalia
  • Nethive
  • Nexthink
  • Nuvis
  • Praim
  • QAD
  • Qualys
  • Red Hot Cyber
  • Riverbed
  • Saviynt
  • Sensormatic
  • SentinelOne
  • Talent Software
  • Vectra
  • Vectra AI
  • Vertiv

Office printing, digital PR, marketing, lead generation: all projects are born from our passion and expertise, with an inevitable touch of creativity and innovation.

COMPANY

Grandangolo Communications Srl
Via Sardegna 19
20146 Milano
Telephone +39 335 8283393
info@grandangolo.it

I SERVIZI

  • Home
  • Company
  • Services
  • Best Practice
  • Customer Press Room
  • Contacts
  • Languages

CONTACTS

  • Contacts
  • Cookie policy
  • Privacy policy

© 2019 GRANDANGOLO COMMUNICATIONS SRL | P.IVA IT 06394850967 | All rights reserveD.

Powered by Webpowerplus

TOP