The evolution of ransomware has entered a phase where disabling security tools is no longer an auxiliary step but a core component of the attack chain. Endpoint Detection and Response (EDR) killers have emerged as one of the most effective mechanisms for adversaries to neutralize defenses before deploying encryption payloads. While much of the industry focus has traditionally been on vulnerable drivers, this perspective alone is insufficient to fully understand the scale and sophistication of the ecosystem.
Recent research reveals a vast and fragmented landscape of EDR killers, ranging from publicly available proof-of-concept (PoC) tools to highly customized and commercialized solutions. Nearly 90 distinct EDR killers are actively used in the wild, spanning ransomware groups of all sizes. Among these, 54 rely on Bring Your Own Vulnerable Driver (BYOVD) techniques, exploiting 35 different drivers, while others use scripts or repurpose legitimate anti-rootkit tools. Notably, at least 24 BYOVD-based tools appear to have been developed independently, without reliance on public PoCs, highlighting growing technical maturity among threat actors.
The popularity of EDR killers stems from their operational efficiency. Ransomware encryptors are inherently noisy due to rapid file modifications, making stealth difficult to maintain. Instead of investing heavily in obfuscating encryptors, attackers opt to disable security solutions entirely. This approach simplifies development, improves reliability, and ensures predictable execution during intrusions.
Another key factor is accessibility. Public PoCs and open-source repositories have effectively democratized kernel-level exploitation. Even low-skilled affiliates can deploy powerful EDR killers with minimal effort. Combined with the use of legitimate signed drivers, this creates a highly effective yet low-cost attack vector that is difficult to mitigate without impacting legitimate software.
Technically, EDR killers fall into several categories. Script-based variants represent the simplest form, using native Windows utilities such as taskkill, net stop, and sc delete to terminate security processes. Although largely outdated, these methods still appear in low-sophistication attacks. More advanced approaches leverage Safe Mode to bypass protections, though this introduces operational risk due to required system reboots.
A more nuanced category involves the abuse of anti-rootkit tools. Originally designed to detect kernel-level threats, tools such as GMER and PC Hunter are now repurposed by attackers to terminate protected processes. Their graphical interfaces lower the barrier to entry, enabling less experienced attackers to disrupt defenses effectively.

The dominant technique, however, remains BYOVD. In this model, attackers deploy legitimate but vulnerable drivers, then exploit them to gain kernel-level access. This allows termination of protected processes and manipulation of system callbacks. Despite the large number of vulnerable drivers available, only a subset is actively used in ransomware campaigns. However, due to the widespread availability of PoCs, these drivers can be reused and adapted across multiple tools and campaigns.
A growing trend is the emergence of driverless EDR killers. Tools such as EDRSilencer and EDR-Freeze bypass kernel exploitation entirely by disrupting communication channels or freezing security processes. Their unconventional nature makes detection more challenging, and their rapid adoption highlights the adaptability of threat actors.
The development ecosystem of EDR killers is equally diverse. While some ransomware operators provide proprietary tools to affiliates, most attackers either modify existing PoCs or purchase tools from underground marketplaces. Commercial offerings have become increasingly sophisticated, featuring obfuscation, anti-analysis techniques, and customer-oriented features such as user-friendly interfaces and support for multiple drivers.
The role of artificial intelligence in this domain is becoming increasingly apparent. Although definitive attribution is difficult, certain code patterns suggest AI-assisted development. Examples include automated error-handling routines and trial-and-error exploitation mechanisms, indicating a shift toward semi-automated malware development.

A critical insight from this research is that vulnerable drivers alone are not reliable indicators for attribution. The same driver can be used across unrelated tools, and individual tools may switch drivers over time. This fluidity underscores the need for broader contextual analysis when investigating ransomware activity.
Defensive strategies must evolve accordingly. While blocking vulnerable drivers is essential, it is often too late in the attack chain. By the time a driver is deployed, attackers typically already have elevated privileges. Moreover, aggressive blocking can disrupt legitimate operations due to the dual-use nature of these drivers.
A more effective approach involves multilayered defense mechanisms that detect and disrupt attackers earlier in the intrusion lifecycle. This includes monitoring behavioral patterns, detecting anomalous privilege escalation, and identifying suspicious tool usage before execution.
| Tactic | ID | Name | Description |
| Execution | T1059.003 | Command and Scripting Interpreter: Windows Command Shell | Script-based EDR killers use taskkill, sc, net stop, and similar commands to tamper with protection. |
| T1569.002 | System Services: Service Execution | EDR killers execute vulnerable drivers as services. | |
| Persistence | T1543.003 | Create or Modify System Process: Windows Service | Some EDR killers may create services to run during Safe Mode or at next boot. |
| T1037.001 | Boot or Logon Initialization Scripts: Logon Script (Windows) | EDR killers register scripts and services to run early at boot to interfere with EDR loading. | |
| Privilege Escalation | T1068 | Exploitation for Privilege Escalation | BYOVD-based EDR killers exploit vulnerable drivers to escalate kernel-level privileges. |
| Defense Evasion | T1562.001 | Impair Defenses: Disable or Modify Tools | EDR killers terminate or suspend EDR/AV processes and services to bypass detection. |
| T1562.009 | Impair Defenses: Safe Mode Boot | Script-based EDR killers reboot systems into Safe Mode to tamper with security components. | |
| T1070.004 | Indicator Removal: File Deletion | EDR killers may attempt to delete EDR/AV files to disable protections. | |
| T1562.006 | Impair Defenses: Indicator Blocking | Driverless EDR killers block telemetry and network communication (e.g., EDRSilencer). | |
| T1027 | Obfuscated Files or Information | Commercial EDR killers especially use obfuscation and encryption (e.g., CardSpaceKiller). | |
| T1027.009 | Obfuscated Files or Information: Embedded Payloads | Some EDR killers embed the drivers directly into their user-mode components, often encrypted. | |
| T1027.002 | Obfuscated Files or Information: Software Packing | Commercial EDR killers rely on packers like HeartCrypt or VX Crypt, and also advanced code protectors like Themida and VMProtect. | |
| T1027.005 | Obfuscated Files or Information: Indicator Removal from Tools | EDR killers like SmilingKiller use control-flow flattening and code obfuscation. | |
| T1140 | Deobfuscate/Decode Files or Information | Some EDR killers store encrypted drivers and shellcode in dedicated files on disk. | |
| Impact | T1490 | Inhibit System Recovery | Some EDR killers delete or rename security-related files, impacting recovery. |
| T1489 | Service Stop | EDR killers stop protected services of security products and tamper with their functionality. |
Indicators of Compromise (IOCs)
Below is a preserved subset of key indicators:
54547180A99474B0DBA289D92C4A8F3EEA78B531 2Gk8.exe AbyssKiller
75F85CAEA52FE5A124FA77E2934ABD3161690ADD smuot.sys ABYSSWORKER rootkit
002573D80091F7F8167BCBDA3A402B85FA915F19 lasdjfioasdjfioer.exe EDRSilencer
1E7567C0D525AD037FBBBAFB643BF40541994411 EDR-Freeze.exe EDR-Freeze
65C2388B0AFB1D1F1860BB887456D8D6CD8B5645 Killer.exe EDRKillShifter
083F604377D74C4377822EF35021E34AD7DACEEA susanoo.exe Susanoo
31CE76931CA09D3918B34E3187703BC72E6D647E TfSysMon-Killer.exe
09735640D6634B0303755A9FD3B2BC80F932126C pip.exe SmilingKiller
711C95FEAD2215E9AC59E32E6E3B0D71AD5C5AA5 demor.exe DemoKiller
Our Opinion on the EDR Killer Ecosystem
The rise of EDR killers reflects a fundamental shift in attacker strategy: rather than evading detection, adversaries are now prioritizing the complete neutralization of defensive systems. This approach is not only more efficient but also aligns perfectly with the ransomware-as-a-service model, where affiliates may lack deep technical expertise but still require reliable outcomes.
What is particularly concerning is the commoditization of these tools. The availability of plug-and-play EDR killers, combined with commercial offerings and AI-assisted development, lowers the barrier to entry significantly. This means that even less sophisticated actors can execute highly impactful attacks, increasing both the frequency and success rate of ransomware incidents.
Equally problematic is the defensive dilemma posed by legitimate vulnerable drivers. Organizations cannot simply block all such drivers without risking operational disruption, creating a persistent blind spot that attackers continue to exploit.
In our view, the industry must move beyond reactive controls and adopt proactive, behavior-driven detection strategies. Focusing solely on indicators such as drivers or hashes is no longer sufficient. Instead, defenders must understand attacker workflows, identify early-stage intrusion signals, and respond decisively before EDR killers are deployed.
Ultimately, the battle against ransomware will be won not by stronger tools alone, but by faster and smarter response strategies.
