EDRKillShifter is a Windows EDR-disruption utility developed and maintained by the RansomHub ransomware-as-a-service operation and provided to affiliates as a proprietary defense-evasion tool. It is designed to disable endpoint protection products prior to ransomware deployment by using a bring-your-own-vulnerable-driver workflow. Security researchers have described it as a loader-style executable that decrypts and launches an embedded payload only when supplied with a unique 64-character command-line password, a mechanism that also hinders sandboxing and analysis.
Operationally, EDRKillShifter deploys a vulnerable signed kernel driver, loads it as a service, and then abuses kernel-level capabilities to enumerate and terminate targeted security processes in a continuous loop. Observed payloads have been written in Go, use obfuscation and self-modifying code, and in some variants support attacker-supplied supplemental target lists. Public proof-of-concept BYOVD exploitation code appears to have been adapted into the tool’s implementation. Multiple builds have been documented using different vulnerable drivers and targeting a range of antivirus and EDR vendors, indicating active maintenance and iterative development.
EDRKillShifter became notable as an exception within the ransomware ecosystem because it was centrally developed by a RaaS operator rather than selected independently by affiliates. It was introduced for affiliate use in 2024 and later observed beyond RansomHub-only intrusions, including operations associated with Medusa, BianLian, and Play, as well as broader reporting tying updated or evolved variants to additional ransomware groups. It has been used in the common pre-encryption sequence of disabling endpoint defenses before follow-on actions such as ransomware execution, data theft, privilege escalation, and lateral movement. Later reporting indicates the original tool was eventually superseded by newer EDR-killing utilities, but EDRKillShifter remains an important example of the commercialization and operational centralization of anti-EDR tooling in ransomware campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
BadRentdrv2 ... rentdrv2ドライバの脆弱性(CVE-2023-44976)を悪用するBYOVD PoC。x32/x64両対応で、EDR/AVプロセスをPID指定で終了可能。RansomHub等のEDRKillShifterでも悪用が確認されている
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
For comparison, ESET notes that RansomHub , another prominent RaaS operation, built a single in-house EDR killer ( EDRKillShifter ) for affiliate use via its affiliate panel.
RansomHub’s EDR killer, named EDRKillShifter by Sophos, is a custom tool developed and maintained by the operator.
Water Bakunawa uses EDRKillShifter to evade detection and disrupt security monitoring processes.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
Some samples, like those documented in early EDRKillShifter research, require a 64-character password supplied on the command line before they will execute, which gates the binary against sandbox analysis.
All samples require a unique 64-character password passed to the command line. If the password is wrong (or not provided), it won’t execute.
The loader unpacks its real payload in memory using self-modifying code.
The original filename is Loader.exe and its product name is ARK-Game. (Some members of the research team speculated that the threat actor tries to masquerade the final payload as a popular computer game named ARK: Survival Evolved.)
It also copies that data into a new file named Config.ini and writes that file to the same filesystem location where the binary was executed... The malware then deletes the config.ini file
When run with the correct password, the executable decrypts an embedded resource named BIN and executes it in memory.
RansomHub’s builder adds an additional layer of protection to its encryptors, a 64-character password, without which the encryptor does not work.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A tool used to evade or disable endpoint detection and response capabilities prior to ransomware deployment.
A kernel-mode EDR killer that disables endpoint agents, with some samples protected by a command-line password to hinder sandbox analysis. The content describes it as part of the same operational pattern leading to ransomware deployment.
An in-house EDR killer associated with the RansomHub RaaS operation, mentioned for comparison with Gentlemen’s broader tooling portfolio.
An EDR killer mentioned as a comparison point for another ransomware operation's affiliate tooling model.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.