National Cyber Warfare Foundation (NCWF)

Hackers Repurpose RansomHub's EDRKillShifter in Medusa, BianLian, and Play Attacks


0 user ratings
2025-03-27 14:44:27
milo
Attacks
A new analysis has uncovered connections between affiliates of RansomHub and other ransomware groups like Medusa, BianLian, and Play.
The connection stems from the use of a custom tool that's designed to disable endpoint detection and response (EDR) software on compromised hosts, according to ESET. The EDR killing tool, dubbed EDRKillShifter, was first documented as used by RansomHub actors in



Source: TheHackerNews
Source Link: https://thehackernews.com/2025/03/hackers-repurpose-ransomhubs.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Attacks



Copyright 2012 through 2025 - National Cyber Warfare Foundation - All rights reserved worldwide.