EDRKillShifter is a Windows loader and endpoint-security-disabling tool developed and maintained by the RansomHub ransomware operation and supplied to its affiliates. Named by Sophos, it uses bring-your-own-vulnerable-driver (BYOVD) techniques to terminate antivirus and endpoint detection and response processes before ransomware deployment. RansomHub introduced the tool through its affiliate panel in May 2024. It has also been observed in intrusions associated with Medusa, BianLian, and Play, including activity attributed to the QuadSwitcher affiliate cluster. CosmicBeetle has also used it as a RansomHub affiliate. Observed victims span manufacturing, automotive, government, legal, and technology organizations in Europe and North America.
Analyzed samples use a multistage execution chain gated by a unique 64-character command-line password. The loader derives a decryption key from the password using SHA-256, decrypts an embedded payload, and executes it in memory. An intermediate stage uses self-modifying code to hinder analysis. The final, obfuscated Go payload deploys a legitimate vulnerable driver and creates and starts a service to load it. Confirmed variants abuse RentDrv2 and ThreatFireMonitor, incorporating techniques from publicly available proof-of-concept exploits. Once the driver is loaded, the payload continuously enumerates running processes and terminates those matching a hardcoded security-process target list; one variant also accepts additional target names supplied by the operator. Repeated termination suppresses security-agent recovery during the attack. EDRKillShifter is deployed on already-compromised systems as a defense-evasion component rather than functioning as a ransomware encryptor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
BadRentdrv2 ... rentdrv2ドライバの脆弱性(CVE-2023-44976)を悪用するBYOVD PoC。x32/x64両対応で、EDR/AVプロセスをPID指定で終了可能。RansomHub等のEDRKillShifterでも悪用が確認されている
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The EDRKillShifter can act as a loader for a vulnerable legitimate driver that, once exploited, can facilitate persistent defense evasion.
RansomHub’s EDR killer, named EDRKillShifter by Sophos, is a custom tool developed and maintained by the operator.
Water Bakunawa uses EDRKillShifter to evade detection and disrupt security monitoring processes.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
Some samples, like those documented in early EDRKillShifter research, require a 64-character password supplied on the command line before they will execute, which gates the binary against sandbox analysis.
All samples require a unique 64-character password passed to the command line. If the password is wrong (or not provided), it won’t execute.
“KillerUltra.exe — a custom-packed executable embedding the Zemana driver as a compiled-in resource”; EDRKillShifter “requires a 64-character password passed on the command line to decrypt its payload.”
The original filename is Loader.exe and its product name is ARK-Game. (Some members of the research team speculated that the threat actor tries to masquerade the final payload as a popular computer game named ARK: Survival Evolved.)
It also copies that data into a new file named Config.ini and writes that file to the same filesystem location where the binary was executed... The malware then deletes the config.ini file
When run with the correct password, the executable decrypts an embedded resource named BIN and executes it in memory.
RansomHub’s builder adds an additional layer of protection to its encryptors, a 64-character password, without which the encryptor does not work.
“The password-gating mechanism serves a dual purpose: it prevents sandbox detonation (the binary appears inert without the correct password).”
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Endpoint-defense termination toolkit mentioned as a comparison to Silver Fox's killer module. The reference describes it as operating against lists containing more than 300 security processes and uses it to illustrate the value of correlating kernel-driver loading with mass security-process termination.
A tool used to evade or disable endpoint detection and response capabilities prior to ransomware deployment.
A kernel-mode EDR killer that disables endpoint agents, with some samples protected by a command-line password to hinder sandbox analysis. The content describes it as part of the same operational pattern leading to ransomware deployment.
An in-house EDR killer associated with the RansomHub RaaS operation, mentioned for comparison with Gentlemen’s broader tooling portfolio.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.