Cybersecurity Panic: EDRKillShifter Tool Targets Endpoint Detection Systems
Cybercrime group RansomHub has unleashed EDRKillShifter, a new tool designed to terminate endpoint detection and response (EDR) software, joining the ranks of other notorious programs. Sophos discovered the tool during a failed ransomware attack, highlighting the evolving tactics of cybercriminals.

Hot Take:
Just when you thought it was safe to go back in the cyber water, RansomHub and its merry band of digital miscreants have unleashed EDRKillShifter, a tool so sneaky it makes Houdini look like an amateur magician. If your EDR software starts acting like it’s on a permanent coffee break, you know who to blame.
Key Points:
- RansomHub gang introduces EDRKillShifter, a new tool for disabling endpoint detection and response (EDR) software.
- EDRKillShifter is a loader executable that uses a ‘bring your own vulnerable driver’ (BYOVD) method.
- Microsoft links RansomHub to the notorious Scattered Spider e-crime syndicate.
- The tool leverages vulnerable drivers to gain elevated privileges and disable EDR software.
- Mitigation strategies include keeping systems updated and separating user and admin privileges.
Already a member? Log in here