Ransomware Gangs Shift Strategy as “EDR Killers” Surge, Exploiting Vulnerable Drivers and Outpacing Traditional Defenses

The evolution of ransomware has entered a phase where disabling security tools is no longer an auxiliary step but a core component of the attack chain. Endpoint Detection and Response (EDR) killers have emerged as one of the most effective mechanisms for adversaries to neutralize defenses before deploying encryption payloads. While much of the industry focus has traditionally been on vulnerable drivers, this perspective alone is insufficient to fully understand the scale and sophistication of the ecosystem.

Recent research reveals a vast and fragmented landscape of EDR killers, ranging from publicly available proof-of-concept (PoC) tools to highly customized and commercialized solutions. Nearly 90 distinct EDR killers are actively used in the wild, spanning ransomware groups of all sizes. Among these, 54 rely on Bring Your Own Vulnerable Driver (BYOVD) techniques, exploiting 35 different drivers, while others use scripts or repurpose legitimate anti-rootkit tools. Notably, at least 24 BYOVD-based tools appear to have been developed independently, without reliance on public PoCs, highlighting growing technical maturity among threat actors.

The popularity of EDR killers stems from their operational efficiency. Ransomware encryptors are inherently noisy due to rapid file modifications, making stealth difficult to maintain. Instead of investing heavily in obfuscating encryptors, attackers opt to disable security solutions entirely. This approach simplifies development, improves reliability, and ensures predictable execution during intrusions.

Another key factor is accessibility. Public PoCs and open-source repositories have effectively democratized kernel-level exploitation. Even low-skilled affiliates can deploy powerful EDR killers with minimal effort. Combined with the use of legitimate signed drivers, this creates a highly effective yet low-cost attack vector that is difficult to mitigate without impacting legitimate software.

Technically, EDR killers fall into several categories. Script-based variants represent the simplest form, using native Windows utilities such as taskkill, net stop, and sc delete to terminate security processes. Although largely outdated, these methods still appear in low-sophistication attacks. More advanced approaches leverage Safe Mode to bypass protections, though this introduces operational risk due to required system reboots.

A more nuanced category involves the abuse of anti-rootkit tools. Originally designed to detect kernel-level threats, tools such as GMER and PC Hunter are now repurposed by attackers to terminate protected processes. Their graphical interfaces lower the barrier to entry, enabling less experienced attackers to disrupt defenses effectively.

The GUI of GMER, a popular anti-rootkit solution

The dominant technique, however, remains BYOVD. In this model, attackers deploy legitimate but vulnerable drivers, then exploit them to gain kernel-level access. This allows termination of protected processes and manipulation of system callbacks. Despite the large number of vulnerable drivers available, only a subset is actively used in ransomware campaigns. However, due to the widespread availability of PoCs, these drivers can be reused and adapted across multiple tools and campaigns.

A growing trend is the emergence of driverless EDR killers. Tools such as EDRSilencer and EDR-Freeze bypass kernel exploitation entirely by disrupting communication channels or freezing security processes. Their unconventional nature makes detection more challenging, and their rapid adoption highlights the adaptability of threat actors.

The development ecosystem of EDR killers is equally diverse. While some ransomware operators provide proprietary tools to affiliates, most attackers either modify existing PoCs or purchase tools from underground marketplaces. Commercial offerings have become increasingly sophisticated, featuring obfuscation, anti-analysis techniques, and customer-oriented features such as user-friendly interfaces and support for multiple drivers.

The role of artificial intelligence in this domain is becoming increasingly apparent. Although definitive attribution is difficult, certain code patterns suggest AI-assisted development. Examples include automated error-handling routines and trial-and-error exploitation mechanisms, indicating a shift toward semi-automated malware development.

Susanoo EDR killer’s loading screen (left) and GUI (right)

A critical insight from this research is that vulnerable drivers alone are not reliable indicators for attribution. The same driver can be used across unrelated tools, and individual tools may switch drivers over time. This fluidity underscores the need for broader contextual analysis when investigating ransomware activity.

Defensive strategies must evolve accordingly. While blocking vulnerable drivers is essential, it is often too late in the attack chain. By the time a driver is deployed, attackers typically already have elevated privileges. Moreover, aggressive blocking can disrupt legitimate operations due to the dual-use nature of these drivers.

A more effective approach involves multilayered defense mechanisms that detect and disrupt attackers earlier in the intrusion lifecycle. This includes monitoring behavioral patterns, detecting anomalous privilege escalation, and identifying suspicious tool usage before execution.

TacticIDNameDescription
ExecutionT1059.003Command and Scripting Interpreter: Windows Command ShellScript-based EDR killers use taskkill, sc, net stop, and similar commands to tamper with protection.
T1569.002System Services: Service ExecutionEDR killers execute vulnerable drivers as services.
PersistenceT1543.003Create or Modify System Process: Windows ServiceSome EDR killers may create services to run during Safe Mode or at next boot.
T1037.001Boot or Logon Initialization Scripts: Logon Script (Windows)EDR killers register scripts and services to run early at boot to interfere with EDR loading.
Privilege EscalationT1068Exploitation for Privilege EscalationBYOVD-based EDR killers exploit vulnerable drivers to escalate kernel-level privileges.
Defense EvasionT1562.001Impair Defenses: Disable or Modify ToolsEDR killers terminate or suspend EDR/AV processes and services to bypass detection.
T1562.009Impair Defenses: Safe Mode BootScript-based EDR killers reboot systems into Safe Mode to tamper with security components.
T1070.004Indicator Removal: File DeletionEDR killers may attempt to delete EDR/AV files to disable protections.
T1562.006Impair Defenses: Indicator BlockingDriverless EDR killers block telemetry and network communication (e.g., EDRSilencer).
T1027Obfuscated Files or InformationCommercial EDR killers especially use obfuscation and encryption (e.g., CardSpaceKiller).
T1027.009Obfuscated Files or Information: Embedded PayloadsSome EDR killers embed the drivers directly into their user-mode components, often encrypted.
T1027.002Obfuscated Files or Information: Software PackingCommercial EDR killers rely on packers like HeartCrypt or VX Crypt, and also advanced code protectors like Themida and VMProtect.
T1027.005Obfuscated Files or Information: Indicator Removal from ToolsEDR killers like SmilingKiller use control-flow flattening and code obfuscation.
T1140Deobfuscate/Decode Files or InformationSome EDR killers store encrypted drivers and shellcode in dedicated files on disk.
ImpactT1490Inhibit System RecoverySome EDR killers delete or rename security-related files, impacting recovery.
T1489Service StopEDR killers stop protected services of security products and tamper with their functionality.

Indicators of Compromise (IOCs)

Below is a preserved subset of key indicators:

54547180A99474B0DBA289D92C4A8F3EEA78B531  2Gk8.exe  AbyssKiller
75F85CAEA52FE5A124FA77E2934ABD3161690ADD smuot.sys ABYSSWORKER rootkit
002573D80091F7F8167BCBDA3A402B85FA915F19 lasdjfioasdjfioer.exe EDRSilencer
1E7567C0D525AD037FBBBAFB643BF40541994411 EDR-Freeze.exe EDR-Freeze
65C2388B0AFB1D1F1860BB887456D8D6CD8B5645 Killer.exe EDRKillShifter
083F604377D74C4377822EF35021E34AD7DACEEA susanoo.exe Susanoo
31CE76931CA09D3918B34E3187703BC72E6D647E TfSysMon-Killer.exe
09735640D6634B0303755A9FD3B2BC80F932126C pip.exe SmilingKiller
711C95FEAD2215E9AC59E32E6E3B0D71AD5C5AA5 demor.exe DemoKiller

Our Opinion on the EDR Killer Ecosystem

The rise of EDR killers reflects a fundamental shift in attacker strategy: rather than evading detection, adversaries are now prioritizing the complete neutralization of defensive systems. This approach is not only more efficient but also aligns perfectly with the ransomware-as-a-service model, where affiliates may lack deep technical expertise but still require reliable outcomes.

What is particularly concerning is the commoditization of these tools. The availability of plug-and-play EDR killers, combined with commercial offerings and AI-assisted development, lowers the barrier to entry significantly. This means that even less sophisticated actors can execute highly impactful attacks, increasing both the frequency and success rate of ransomware incidents.

Equally problematic is the defensive dilemma posed by legitimate vulnerable drivers. Organizations cannot simply block all such drivers without risking operational disruption, creating a persistent blind spot that attackers continue to exploit.

In our view, the industry must move beyond reactive controls and adopt proactive, behavior-driven detection strategies. Focusing solely on indicators such as drivers or hashes is no longer sufficient. Instead, defenders must understand attacker workflows, identify early-stage intrusion signals, and respond decisively before EDR killers are deployed.

Ultimately, the battle against ransomware will be won not by stronger tools alone, but by faster and smarter response strategies.