{"id":4705,"date":"2025-07-19T13:40:55","date_gmt":"2025-07-19T13:40:55","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=4705"},"modified":"2025-07-19T13:40:56","modified_gmt":"2025-07-19T13:40:56","slug":"shifting-the-sands-of-ransomhubs-edrkillshifter","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=4705","title":{"rendered":"Shifting the sands of RansomHub\u2019s EDRKillShifter"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p>ESET researchers have a look again on the vital adjustments within the ransomware ecosystem in 2024 and deal with the newly emerged and at the moment dominating ransomware-as-a-service (RaaS) gang, RansomHub. We share beforehand unpublished insights into RansomHub\u2019s affiliate construction and uncover clear connections between this newly emerged large and well-established gangs Play, Medusa, and BianLian.<\/p>\n<p>We additionally emphasize the rising risk of EDR killers, unmasking EDRKillShifter, a customized EDR killer developed and maintained by RansomHub. Now we have noticed a rise in ransomware associates utilizing code derived from publicly out there proofs of idea, whereas the set of drivers being abused is basically fastened.<\/p>\n<p>Lastly, primarily based on our observations following the law-enforcement-led Operation Cronos and the demise of the notorious BlackCat gang, we provide our insights into how one can help on this intensive struggle in opposition to ransomware.<\/p>\n<blockquote>\n<p><strong>Key factors of this blogpost:<\/strong><\/p>\n<ul>\n<li>We found clear hyperlinks between the RansomHub, Play, Medusa, and BianLian ransomware gangs.<\/li>\n<li>We achieved this by following the path of tooling that RansomHub gives its associates.<\/li>\n<li>We doc extra findings about EDRKillShifter, correlating our observations with RansomHub\u2019s public exercise.<\/li>\n<li>We provide insights into the rising risk of EDR killers, their anatomy, and their position within the ransomware world.<\/li>\n<\/ul>\n<\/blockquote>\n<h2>Overview<\/h2>\n<p>The struggle in opposition to ransomware reached two milestones in 2024: <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.europol.europa.eu\/media-press\/newsroom\/news\/law-enforcement-disrupt-worlds-biggest-ransomware-operation\" target=\"_blank\" rel=\"noopener\">LockBit<\/a> and <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.justice.gov\/archives\/opa\/pr\/justice-department-disrupts-prolific-alphvblackcat-ransomware-variant\" target=\"_blank\" rel=\"noopener\">BlackCat<\/a>, previously the highest two gangs, dropped out of the image. And for the primary time since 2022, recorded ransomware funds dropped, particularly by a <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.chainalysis.com\/blog\/crypto-crime-ransomware-victim-extortion-2025\/\" target=\"_blank\" rel=\"noopener\">gorgeous 35%<\/a> regardless of reverse <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.chainalysis.com\/blog\/2024-crypto-crime-mid-year-update-part-1\/\" target=\"_blank\" rel=\"noopener\">expectations in the course of the yr<\/a>. Then again, the recorded variety of victims posted on devoted leak websites (DLSs) elevated by roughly 15%.<\/p>\n<p>An enormous a part of this improve is because of RansomHub, a brand new RaaS gang that emerged across the time of <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.europol.europa.eu\/media-press\/newsroom\/news\/law-enforcement-disrupt-worlds-biggest-ransomware-operation\" target=\"_blank\" rel=\"noopener\">Operation Cronos<\/a>. On this blogpost, we glance in depth at RansomHub and reveal how we leveraged to our benefit the best way associates use RansomHub\u2019s tooling, permitting us to attract connections between RansomHub and its rivals, together with well-established ones like <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\/aa23-352a\" target=\"_blank\" rel=\"noopener\">Play<\/a>, <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/unit42.paloaltonetworks.com\/medusa-ransomware-escalation-new-leak-site\/\" target=\"_blank\" rel=\"noopener\">Medusa<\/a>, and <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\/aa23-136a\">BianLian<\/a>.<\/p>\n<p>All through this blogpost, we confer with entities forming the ransomware-as-a-service mannequin as follows:<\/p>\n<ul>\n<li><strong>Operators<\/strong>, who develop the ransomware payload, keep the DLS, and provide companies to associates, often for a month-to-month charge and a proportion of the ransom cost (sometimes 5\u201320%).<\/li>\n<li><strong>Associates<\/strong>, who hire ransomware companies from operators, and deploy the encryptors to victims\u2019 networks and generally additionally follow information exfiltration.<\/li>\n<\/ul>\n<h2>The rise of RansomHub<\/h2>\n<p>RansomHub introduced its first sufferer on its DLS (see Determine 1) on February 10<sup>th<\/sup>, 2024, 10 days earlier than the general public announcement of Operation Cronos. Whereas the gang\u2019s rise was gradual, it was additionally constant, and when \u2013 in April 2024 \u2013 RansomHub achieved probably the most sufferer postings of all lively ransomware teams (disregarding <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.theregister.com\/2024\/05\/22\/lockbit_dethroned_as_leading_ransomware\/\" target=\"_blank\" rel=\"noopener\">LockBit posting fakes<\/a>), it was clear that this was a gang to maintain an in depth eye on. Since then, RansomHub has dominated the ransomware scene.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 1. RansomHub\u2019s DLS\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2025\/03-25\/ransomhub\/figure-1.png\" alt=\"Figure 1. RansomHub\u2019s DLS\" width=\"\" height=\"\"\/><figcaption><em>Determine 1. RansomHub\u2019s DLS<\/em><\/figcaption><\/figure>\n<p>To additional reveal how harmful RansomHub is, let\u2019s examine it to LockBit. Determine 2 exhibits the day by day cumulative sum (on the y-axis) of recent victims posted on the DLS of LockBit vs. RansomHub, ranging from RansomHub\u2019s look in February 2024.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 2. Progression of DLS posts by RansomHub and LockBit since RansomHub\u2019s appearance. Souce: ecrime.ch\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2025\/03-25\/ransomhub\/figure-2.png\" alt=\"Figure 2. Progression of DLS posts by RansomHub and LockBit since RansomHub\u2019s appearance\" width=\"\" height=\"\"\/><figcaption><em>Determine 2. Development of DLS posts by RansomHub and LockBit since RansomHub\u2019s look. Souce: <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/ecrime.ch\/\" target=\"_blank\" rel=\"noopener\">ecrime.ch<\/a><\/em><\/figcaption><\/figure>\n<p>As you may clearly see, whereas RansomHub began saying victims extra slowly, practically 9 months later the gang was capable of accumulate extra victims because it began than LockBit, and that development continues to today. Contemplating that each BlackCat and LockBit suffered large blows proper across the time RansomHub emerged, we are able to confidently assume that many expert associates migrated to RansomHub; <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/krebsonsecurity.com\/2024\/03\/blackcat-ransomware-group-implodes-after-apparent-22m-ransom-payment-by-change-healthcare\/\" target=\"_blank\" rel=\"noopener\">Notchy<\/a>, the BlackCat affiliate who stole greater than 4 TB of knowledge from Change Healthcare, is only one publicly recognized instance.<\/p>\n<p>Determine 3 exhibits the ransom be aware that RansomHub associates depart on their victims\u2019 machines.<\/p>\n<pre style=\"background-color: #f5f5f5; border: 1px solid #ddd; padding: 10px; line-height: 1.25; margin: 0;\"><code style=\"white-space: pre-wrap;\">We're the RansomHub.\n\nYour organization Servers are locked and Information has been taken to our servers. That is critical. \n\nExcellent news:\n- your server system and information shall be restored by our Decryption Device, we assist trial decryption to show that your recordsdata could be decrypted;\n- for now, your information is secured and safely saved on our server;\n- no person on the planet is conscious in regards to the information leak out of your firm besides you and RansomHub staff;\n- we offer free trial decryption for recordsdata smaller than 1MB. If anybody claims they will decrypt our recordsdata, you may ask them to attempt to decrypt a file bigger than 1MB.\n\nFAQs:\nWho we're?\n- Regular Browser Hyperlinks: https:\/\/ransomxifxwc5eteopdobynonjctkxxvap77yqifu2emfbecgbqdw6qd.onion.ly\/\n- Tor Browser Hyperlinks: http:\/\/ransomxifxwc5eteopdobynonjctkxxvap77yqifu2emfbecgbqdw6qd.onion\/\n\nWish to go to authorities for defense?\n- Searching for their assistance will solely make the state of affairs worse,They may attempt to forestall you from negotiating with us, as a result of the negotiations will make them look incompetent,After the incident report is handed over to the federal government division, you may be fined <this will=\"\" be=\"\" a=\"\" huge=\"\" amount=\"\" more=\"\" about=\"\" the=\"\" gdrp=\"\" legislation:https:=\"\">,The federal government makes use of your high quality to reward them.And you'll not get something, and besides you and your organization, the remainder of the individuals will neglect what occurred!!!!!\n\nSuppose you may deal with it with out us by decrypting your servers and information utilizing some IT Answer from third-party \"specialists\"?\n- they'll solely make vital injury to your entire information; each encrypted file shall be corrupted endlessly. Solely our Decryption Device will make decryption assured;  \n\nDo not go to restoration corporations, they're basically simply middlemen who will generate profits off you and cheat you. \n- We're nicely conscious of circumstances the place restoration corporations inform you that the ransom worth is 5 million {dollars}, however in truth they secretly negotiate with us for 1 million {dollars}, in order that they earn 4 million {dollars} from you. If you happen to approached us immediately with out intermediaries you'd pay 5 occasions much less, that's 1 million {dollars}.\n\nSuppose your companion IT Restoration Firm will do recordsdata restoration? \n- no they won't do restoration, solely take 3-4 weeks for nothing; apart from your entire information is on our servers and we are able to publish it at any time; \n  in addition to ship the data in regards to the information breach out of your firm servers to your key companions and shoppers, rivals, media and youtubers, and so forth. \n  These actions from our aspect in direction of your organization may have irreversible detrimental penalties for your small business status.\n\nYou do not care in any case, since you simply do not wish to pay? \n- We'll make you enterprise cease endlessly by utilizing all of our expertise to make your companions, shoppers, workers and whoever cooperates together with your firm change their minds by having no alternative however to keep away from your organization. \n  In consequence, in midterm you'll have to shut your small business. \n\n\nSo lets get straight to the purpose.\n\nWhat do we provide in change in your cost:\n- decryption and restoration of all of your programs and information inside 24 hours with assure;\n- by no means inform anybody in regards to the information breach out out of your firm;\n- after information decryption and system restoration, we'll delete your entire information from our servers endlessly;\n- present priceless advising in your firm IT safety so nobody can assault your once more.```\n\nNow, with a purpose to begin negotiations, you should do the next: \n- set up and run 'Tor Browser' from https:\/\/www.torproject.org\/obtain\/\n- use 'Tor Browser' open http:\/\/ubfofxonwdb32wpcmgmcpfos5tdskfizdft6j54l76x3nrwu2idaigid.onion\/\n- enter your Consumer ID: [REDACTED]\n* don't leak your ID or you may be banned and can by no means be capable of decrypt your recordsdata.\n\nThere shall be no dangerous information to your firm after profitable negotiations for either side. However there shall be loads of these dangerous information if case of failed negotiations, so do not take into consideration how one can keep away from it.\nSimply deal with negotiations, cost and decryption to make your entire issues solved by our specialists inside 1 day after cost acquired: servers and information restored, every part will work good as new.\n\n************************************************<\/this><\/code><\/pre>\n<p style=\"text-align: center;\"><em>Determine 3. RansomHub ransom be aware<\/em><\/p>\n<h3>Recruiting section<\/h3>\n<p>Simply as any rising RaaS gang, RansomHub wanted to draw associates, and since there&#8217;s energy in numbers, the operators weren\u2019t very choosy. The preliminary commercial was posted on the Russian-speaking RAMP discussion board on February 2<sup>nd<\/sup>, 2024, eight days earlier than the primary victims had been posted. There are some things to notice in regards to the preliminary announcement:<\/p>\n<ul>\n<li>Associates can obtain ransoms with their very own pockets after which afterward pay the operator.<\/li>\n<li>Associates get to maintain 90% of the ransom.<\/li>\n<li>The encryptor is obfuscated and helps Home windows, Linux, and ESXi platforms.<\/li>\n<li>RansomHub gives varied methods to enter its RaaS program:\n<ul>\n<li>Suggestion by an current affiliate.<\/li>\n<li>Proof of status.<\/li>\n<li>Proof of previous RaaS cooperation.<\/li>\n<li>Paying a deposit that&#8217;s returned after first profitable cost.<\/li>\n<\/ul>\n<\/li>\n<li>Attacking <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/en.wikipedia.org\/wiki\/Commonwealth_of_Independent_States\" target=\"_blank\" rel=\"noopener\">Commonwealth of Impartial States<\/a>, Cuba, North Korea, and China is prohibited.<\/li>\n<li>Most well-liked communication is over <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/qtox.github.io\/\">qTox<\/a> utilizing the ID <span style=\"font-family: courier new, courier, monospace;\">4D598799696AD5399FABF7D40C4D1BE9F05D74CFB311047D7391AC0BF64BED47B56EEE66A528<\/span>.<\/li>\n<\/ul>\n<p>Ensures like receiving ransom cost on to the affiliate\u2019s pockets and retaining a beneficiant 90% actually sound promising, particularly within the chaos following the BlackCat and LockBit disruptions. Moreover, the entry barrier may be very low, permitting even low-skilled associates to attempt their luck.<\/p>\n<p>Additionally it is value mentioning that RansomHub\u2019s encryptor just isn&#8217;t written from scratch, however primarily based on repurposed code from Knight, a once-rival ransomware gang that <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/knight-ransomware-source-code-for-sale-after-leak-site-shuts-down\/\">bought its supply code<\/a> in February 2024. The associates request the encryptor (usually referred to as a locker by RaaS operators) by means of the net panel provided by RansomHub (as is typical for RaaS gangs); the part chargeable for producing the encryptor is usually known as a builder. As a result of data such because the distinctive sufferer ID is hardcoded within the encryptor, an affiliate must request a brand new one for each sufferer. RansomHub\u2019s builder provides an extra layer of safety to its encryptors, a 64-character password, with out which the encryptor doesn&#8217;t work. This password is exclusive for every pattern, generated by the builder, and recognized solely to the affiliate who requested the encryptor.<\/p>\n<p>On June 21<sup>st<\/sup>, 2024, RansomHub operators modified the affiliate guidelines in response to an alleged breach by safety researchers. In response, the operator now not allowed vouching by current members as ample and strictly required a US$ 5,000 deposit for aspiring associates. This was the final noteworthy message from the RansomHub operators. Nevertheless, between the preliminary announcement and this rule change, yet another necessary occasion occurred, which we dive into within the subsequent part.<\/p>\n<h3>Increasing the arsenal \u2013 EDRKillShifter<\/h3>\n<p>On Could 8<sup>th<\/sup>, 2024, the RansomHub operators made a major replace \u2013 they launched their very own EDR killer, a particular sort of malware designed to terminate, blind, or crash the safety product put in on a vicim\u2019s system, sometimes by abusing a weak driver.<\/p>\n<p>RansomHub\u2019s EDR killer, named EDRKillShifter by <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/news.sophos.com\/en-us\/2024\/08\/14\/edr-kill-shifter\/\" target=\"_blank\" rel=\"noopener\">Sophos<\/a>, is a customized instrument developed and maintained by the operator. EDRKillShifter is obtainable to RansomHub associates by means of the net panel, identical because the encryptor; it too is protected by a 64-character password. Performance-wise, it&#8217;s a typical EDR killer focusing on a big number of safety options that the RansomHub operators anticipate finding defending the networks they purpose to breach. A notable distinction lies within the code safety \u2013 the password protects shellcode that acts as a center layer of the killer\u2019s execution. With out the password, safety researchers can neither retrieve the listing of focused course of names nor the abused weak driver.<\/p>\n<p>Sophos in all probability selected \u201cshifter\u201d within the title to replicate the truth that the abused driver just isn&#8217;t at all times the identical \u2013 not less than two totally different weak drivers (abused by different recognized EDR killers too) had been noticed. We dive extra in depth into EDRKillShifter and different EDR killers within the <em><a rel=\"nofollow\" target=\"_blank\" href=\"#EDR killers on the rise\">EDR killers on the rise<\/a><\/em> part.<\/p>\n<p>The choice to implement a killer and provide it to associates as a part of the RaaS program is uncommon. Associates are sometimes on their very own to seek out methods to evade safety merchandise \u2013 some reuse current instruments, whereas extra technically oriented ones modify current proofs of idea or make the most of EDR killers <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/news.sophos.com\/en-us\/2023\/04\/19\/aukill-edr-killer-malware-abuses-process-explorer-driver\/\" target=\"_blank\" rel=\"noopener\">out there as a service on the darkish internet<\/a>. Evidently, ransomware associates thought this was a good suggestion, as a result of quickly after the announcement, ESET researchers noticed a steep improve in the usage of EDRKillShifter, and never completely in RansomHub circumstances, as we reveal within the subsequent part.<\/p>\n<p>Roughly a month after EDRKillShifter\u2019s announcement, on June 3<sup>rd<\/sup>, 2024, RansomHub operators posted yet one more replace, stating that they improved EDRKillShifter. ESET telemetry exhibits that some associates deployed this up to date model solely 4 days later.<\/p>\n<h2>Leveraging EDRKillShifter<\/h2>\n<p>ESET researchers took benefit of the broad recognition that EDRKillShifter gained upon its launch to develop our analysis. We had been capable of leverage its utilization to affiliate RansomHub associates with the a number of rival gangs that additionally they work for, in addition to to retrieve clearer inside versioning of this EDR killer.<\/p>\n<h3>Linking associates to rival gangs<\/h3>\n<p>The distinction between RansomHub\u2019s encryptor and EDRKillShifter is that there is no such thing as a cause for associates to construct a brand new pattern of EDRKillShifter for each intrusion (until there&#8217;s a main replace) \u2013 which is strictly what allowed us to uncover one in all RansomHub\u2019s associates working for 3 rival gangs \u2013 Play, Medusa, and BianLian.<\/p>\n<p>These three gangs differ considerably:<\/p>\n<ul>\n<li>BianLian focuses totally on extortion-only assaults, with no RaaS program providing on its DLS.<\/li>\n<li>Medusa doesn&#8217;t provide a RaaS program on its DLS both, however advertises its RaaS program on the RAMP underground discussion board.<\/li>\n<li>Play strictly denies ever operating a RaaS program on its DLS.<\/li>\n<\/ul>\n<p>Discovering a hyperlink between RansomHub and Medusa just isn&#8217;t that shocking, as it&#8217;s common data that ransomware associates usually work for a number of operators concurrently. Nevertheless, we didn&#8217;t count on well-established gangs working below the closed RaaS mannequin (that means that they don&#8217;t actively search for new recruits and their partnerships are primarily based on long-term mutual belief) to kind alliances with RansomHub so shortly. Different well-established gangs, along with BianLian and Play, additionally function below the closed RaaS mannequin \u2013 the latest <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/x.com\/PRODAFT\/status\/1892636346885235092\" target=\"_blank\" rel=\"noopener\">BlackBasta leak<\/a> provided distinctive perception into the interior workings of such teams.<\/p>\n<p>One method to clarify Play and BianLian gaining access to EDRKillShifter is that they employed the identical RansomHub affiliate, which is unlikely given the closed nature of each gangs. One other, extra believable clarification is that trusted members of Play and BianLian are collaborating with rivals, even newly emerged ones like RansomHub, after which repurposing the tooling they obtain from these rivals in their very own assaults. That is particularly attention-grabbing, since such closed gangs sometimes make use of a reasonably constant set of core instruments throughout their intrusions. Earlier than diving into the specifics of the found overlaps, let\u2019s briefly introduce the modus operandi of the Play gang.<\/p>\n<h4>Play\u2019s modus operandi<\/h4>\n<p>The Play gang posted the primary victims to its DLS on November 26<sup>th<\/sup>, 2022; the gang has proven regular progress since then. In April 2024, Play made it to the highest three most lively ransomware gangs on the scene and constantly remained within the prime 10 for the entire yr. The gang posts 25 new victims every month, on common, specializing in SMBs, hinting that the gang has not less than a number of skilled, loyal associates. Not too long ago, Play has been <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/unit42.paloaltonetworks.com\/north-korean-threat-group-play-ransomware\/\">linked<\/a> to the North Korea-aligned group Andariel.<\/p>\n<p>As anticipated from a closed RaaS gang, most circumstances involving the Play encryptor present similarities. Usually, in such intrusions:<\/p>\n<ul>\n<li>the encryptors are saved in <span style=\"font-family: courier new, courier, monospace;\">%PUBLICpercentMusic&lt;6_random_alphanumeric_characters&gt;.exe<\/span>,<\/li>\n<li><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/malpedia.caad.fkie.fraunhofer.de\/details\/win.systembc\" target=\"_blank\" rel=\"noopener\">SystemBC<\/a> is utilized for payload supply and serves as a proxy,<\/li>\n<li><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.security.com\/threat-intelligence\/play-ransomware-volume-shadow-copy\" target=\"_blank\" rel=\"noopener\">Grixba<\/a>, a customized community scanner, is usually used, and<\/li>\n<li>extra tooling is usually downloaded immediately from an IP tackle.<\/li>\n<\/ul>\n<p>The rest of the assault sometimes employs a large arsenal of instruments, in addition to living-off-the-land strategies.<\/p>\n<h4>The puzzle<\/h4>\n<p>Let\u2019s look in depth on the hyperlinks we found. We emphasize first crucial ones in Determine 4 after which dive into the main points of every of the intrusions. We consider with excessive confidence that each one these assaults had been carried out by the identical risk actor, working as an affiliate of the 4 ransomware gangs proven in Determine 4. We&#8217;re not monitoring this risk actor below a devoted title at this level, however for comfort, we\u2019ll confer with this risk actor as QuadSwitcher.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 4. Schematic overview of the links between Medusa, RansomHub, BianLian, and Play\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2025\/03-25\/ransomhub\/figure-4.png\" alt=\"Figure 4. Schematic overview of the links between Medusa, RansomHub, BianLian, and Play\" width=\"\" height=\"\"\/><figcaption><em>Determine 4. Schematic overview of the hyperlinks between Medusa, RansomHub, BianLian, and Play<\/em><\/figcaption><\/figure>\n<p>As you may see in Determine 4, there are a complete of 5 intrusions from 4 totally different ransomware gangs interlinked by:<\/p>\n<ul>\n<li>two EDRKillShifter samples (SHA-1: <span style=\"font-family: courier new, courier, monospace;\">BF84712C5314DF2AA851B8D4356EA51A9AD50257<\/span> and <span style=\"font-family: courier new, courier, monospace;\">77DAF77D9D2A08CC22981C004689B870F74544B5<\/span>),<\/li>\n<li>the payload supply server <span style=\"font-family: courier new, courier, monospace;\">45.32.206[.]169<\/span> internet hosting EDRKillShifter and <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/github.com\/AngleHony\/WKTools\" target=\"_blank\" rel=\"noopener\">WKTools<\/a> (a utility to discover and modify the Home windows kernel, utilized in many Play intrusions), and<\/li>\n<li><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/malpedia.caad.fkie.fraunhofer.de\/details\/win.systembc\">SystemBC<\/a> with C&amp;C server <span style=\"font-family: courier new, courier, monospace;\">45.32.210[.]151<\/span>.<\/li>\n<\/ul>\n<p>The next sections go into the person intrusions in additional element.<\/p>\n<h5>RansomHub<\/h5>\n<p>In July 2024, QuadSwitcher deployed the RansomHub encryptor together with EDRKillShifter (SHA-1: <span style=\"font-family: courier new, courier, monospace;\">BF84712C5314DF2AA851B8D4356EA51A9AD50257<\/span>) to a producing firm in Western Europe and an automotive firm in Central Europe.<\/p>\n<p>In August, QuadSwitcher compromised a governmental establishment in North America utilizing <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.putty.org\/\" target=\"_blank\" rel=\"noopener\">PuTTY<\/a>, and shortly after <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/software\/S1040\/\">Rclone<\/a>. They proceeded by putting in <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/anydesk.com\/en\">AnyDesk<\/a> and defending it with a password through a PowerShell script, <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/github.com\/ForbiddenProgrammer\/conti-pentester-guide-leak\/blob\/main\/MANUALS\/%D0%97%D0%B0%D0%BA%D1%80%D0%B5%D0%BF%20AnyDesk.txt\" target=\"_blank\" rel=\"noopener\">anydes.ps1<\/a> (a part of the <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/krebsonsecurity.com\/2022\/03\/conti-ransomware-group-diaries-part-i-evasion\/\" target=\"_blank\" rel=\"noopener\">Conti leaks<\/a>). Making an attempt to evade the safety resolution, the risk actor deployed EDRKillShifter (SHA-1: <span style=\"font-family: courier new, courier, monospace;\">BF84712C5314DF2AA851B8D4356EA51A9AD50257<\/span>) and <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.threatdown.com\/blog\/new-ransomhub-attack-uses-tdskiller-and-lazagne-disables-edr\/\">TDSSKiller<\/a>.<\/p>\n<h5>BianLian<\/h5>\n<p>On the finish of July 2024, QuadSwitcher compromised an organization within the authorized sector in North America. Throughout that intrusion, the risk actor dumped the Energetic Listing by executing<\/p>\n<p><span style=\"font-family: courier new, courier, monospace;\">powershell &#8220;ntdsutil.exe &#8216;ac i ntds&#8217; &#8216;ifm&#8217; &#8216;create full c:temp1&#8217; q q&#8221;,<\/span><\/p>\n<p>deployed AnyDesk through the identical set up script from the Conti leaks, and used <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.advanced-ip-scanner.com\/\">Superior IP Scanner<\/a> to scan the community. Six days later, the attacker put in the <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.screenconnect.com\/\" target=\"_blank\" rel=\"noopener\">ScreenConnect<\/a> and <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.ammyy.com\/en\/\" target=\"_blank\" rel=\"noopener\">Ammyy Admin<\/a> distant monitoring and administration (RMM) instruments and deployed EDRKillShifter (SHA-1: <span style=\"font-family: courier new, courier, monospace;\">BF84712C5314DF2AA851B8D4356EA51A9AD50257<\/span>). After nearly a month of no exercise, the attacker returned and downloaded two payloads from <span style=\"font-family: courier new, courier, monospace;\">http:\/\/45.32.206[.]169\/<\/span>:<\/p>\n<ul>\n<li><span style=\"font-family: courier new, courier, monospace;\">WKTools.exe<\/span>, the WKTools, utility usually utilized by Play<\/li>\n<li><span style=\"font-family: courier new, courier, monospace;\">Killer.exe<\/span>, an occasion of EDRKillShifter (SHA-1: <span style=\"font-family: courier new, courier, monospace;\">77DAF77D9D2A08CC22981C004689B870F74544B5<\/span>)<\/li>\n<\/ul>\n<p>Moreover, QuadSwitcher deployed SystemBC utilizing <span style=\"font-family: courier new, courier, monospace;\">45.32.210[.]151<\/span> as its C&amp;C server, and a <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/redacted.com\/blog\/bianlian-ransomware-gang-gives-it-a-go\/\" target=\"_blank\" rel=\"noopener\">signature BianLian backdoor<\/a> with C&amp;C server <span style=\"font-family: courier new, courier, monospace;\">92.243.64[.]200:6991<\/span> from <span style=\"font-family: courier new, courier, monospace;\">http:\/\/149.154.158[.]222:33031\/win64_1.exe<\/span>. The sufferer was later introduced on BianLian\u2019s DLS.<\/p>\n<h5>Play<\/h5>\n<p>In early August 2024, QuadSwitcher compromised a producing firm in North America. They deployed SystemBC with C&amp;C <span style=\"font-family: courier new, courier, monospace;\">45.32.210[.]151<\/span>, EDRKillShifter (SHA-1: <span style=\"font-family: courier new, courier, monospace;\">77DAF77D9D2A08CC22981C004689B870F74544B5<\/span>), and WKTools, downloaded from <span style=\"font-family: courier new, courier, monospace;\">http:\/\/45.32.206[.]169\/WKTools.exe<\/span>. Finally, the risk actor deployed the Play encryptor.<\/p>\n<h5>Medusa<\/h5>\n<p>On the finish of August 2024, QuadSwitcher compromised a expertise firm in Western Europe, downloading PuTTY from <span style=\"font-family: courier new, courier, monospace;\">http:\/\/130.185.75[.]198:8000\/plink.exe<\/span> utilizing <span style=\"font-family: courier new, courier, monospace;\">certutil.exe<\/span>, adopted by utilizing <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/learn.microsoft.com\/en-us\/sysinternals\/downloads\/process-explorer\">Course of Explorer<\/a> and EDRKillShifter (SHA-1: <span style=\"font-family: courier new, courier, monospace;\">BF84712C5314DF2AA851B8D4356EA51A9AD50257<\/span>). The risk actor additionally downloaded <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/github.com\/Ylianst\/MeshAgent\">MeshAgent<\/a> from <span style=\"font-family: courier new, courier, monospace;\">http:\/\/79.124.58[.]130\/dl\/git.exe<\/span>, additionally through <span style=\"font-family: courier new, courier, monospace;\">certutil.exe<\/span>. The sufferer was later introduced on Medusa\u2019s DLS.<\/p>\n<h3>The puzzle \u2013 conclusion<\/h3>\n<p>Moreover the hyperlinks summarized in Determine 4, there are TTPs that almost all resemble typical Play intrusions. In three of the circumstances, extra malware and instruments had been downloaded from a root folder of a server accessed through an IP tackle utilizing HTTP and QuadSwitcher additionally used SystemBC, commodity malware closely utilized by the Play gang. These hyperlinks lead us to consider QuadSwitcher is said to Play the closest.<\/p>\n<p>Moreover, QuadSwitcher has entry to not less than two EDRKillShifter samples, compiled two months aside, signaling the risk actor had prolonged entry to RansomHub\u2019s tooling.<\/p>\n<h3>Reconstructing EDRKillShifter improvement timeline<\/h3>\n<p>In September 2024, ESET researchers <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.welivesecurity.com\/en\/eset-research\/cosmicbeetle-steps-up-probation-period-ransomhub\/\" target=\"_blank\" rel=\"noopener\">documented<\/a> a case the place CosmicBeetle, an immature ransomware risk actor utilizing its personal signature encryptor, ScRansom, and the leaked LockBit 3.0 builder, turned an affiliate of RansomHub. Observe that CosmicBeetle just isn&#8217;t a gang, however a person distributing and growing varied ransomware. Following the publication of our findings, we noticed CosmicBeetle additional make the most of EDRKillShifter throughout:<\/p>\n<ul>\n<li>a RansomHub assault in opposition to a hospitality firm in South America in August 2024,<\/li>\n<li>a pretend LockBit assault in opposition to an automotive firm in Central Europe in August 2024,<\/li>\n<li>a pretend LockBit assault in opposition to a producing firm in East Asia in September 2024, and<\/li>\n<li>an assault with no encryptor deployed in opposition to an unknown firm within the Center East in January 2025.<\/li>\n<\/ul>\n<p>Different immature ransomware associates had been noticed utilizing EDRKillShifter earlier than deploying their customized encryptors (usually created just by utilizing the leaked LockBit 3.0 builder) as nicely. This exhibits one weak point of RansomHub \u2013 in its greed to develop as shortly as attainable, it wasn\u2019t very choosy about its associates. In consequence, it was, by its personal admission, breached by safety researchers in June 2024. Moreover, immature associates have a tendency to depart considerably extra trails, which enabled us to be taught extra about each them and RansomHub.<\/p>\n<p>Within the blogpost about CosmicBeetle, we talked about EDRKillShifter being deployed from an uncommon path <span style=\"font-family: courier new, courier, monospace;\">C:UsersAdministratorMusic1.0.8.zip<\/span>. Within the following months, a number of different immature associates left comparable trails that enabled us to partially reconstruct EDRKillShifter\u2019s versioning, demonstrated in Desk 1. The VERSIONINFO column refers to EDRKillShifter\u2019s model as listed in its <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/learn.microsoft.com\/en-us\/windows\/win32\/menurc\/vs-versioninfo\" target=\"_blank\" rel=\"noopener\">VERSIONINFO useful resource<\/a>, whereas the Deployment path refers back to the model talked about within the path found by ESET telemetry.<\/p>\n<p style=\"break-after: avoid; text-align: center;\"><em>Desk 1. EDRKillShifter versioning<\/em><\/p>\n<table border=\"1\" width=\"642\" cellspacing=\"0\" cellpadding=\"0\">\n<thead>\n<tr>\n<td width=\"207\"><strong>Compilation date<\/strong><\/td>\n<td width=\"207\"><strong>VERSIONINFO<\/strong><\/td>\n<td width=\"207\"><strong>Deployment path<\/strong><\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td width=\"207\">2024-05-01<\/td>\n<td width=\"207\">1.2.0.1<\/td>\n<td width=\"207\">N\/A<\/td>\n<\/tr>\n<tr>\n<td width=\"207\">2024-06-06<\/td>\n<td width=\"207\">1.2.0.1<\/td>\n<td width=\"207\">1.0.7 \/ 1.0.8<\/td>\n<\/tr>\n<tr>\n<td width=\"207\">2024-06-07<\/td>\n<td width=\"207\">1.6.0.1<\/td>\n<td width=\"207\">2.0.1<\/td>\n<\/tr>\n<tr>\n<td width=\"207\">2024-07-10<\/td>\n<td width=\"207\">2.6.0.1<\/td>\n<td width=\"207\">2.0.4<\/td>\n<\/tr>\n<tr>\n<td width=\"207\">2024-07-24<\/td>\n<td width=\"207\">2.6.0.1<\/td>\n<td width=\"207\">2.0.5<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Following July 2024, there was solely a single very generic replace from the RansomHub operator posted on RAMP, correlating with our not seeing new variations of EDRKillShifter within the wild. Reconstructing the event timeline of EDRKillShifter additionally allowed us to identify these improvement practices:<\/p>\n<ul>\n<li>The <span style=\"font-family: courier new, courier, monospace;\">InternalName<\/span> property of the model data useful resource being both <span style=\"font-family: courier new, courier, monospace;\">Config.exe<\/span> or <span style=\"font-family: courier new, courier, monospace;\">Loader.exe<\/span>.<\/li>\n<li>The <span style=\"font-family: courier new, courier, monospace;\">OriginalName<\/span> property of the model data useful resource at all times being <span style=\"font-family: courier new, courier, monospace;\">Loader.exe<\/span>.<\/li>\n<li>The deployment filename various, mostly being <span style=\"font-family: courier new, courier, monospace;\">Killer.exe<\/span>, <span style=\"font-family: courier new, courier, monospace;\">Magic.exe<\/span>, or <span style=\"font-family: courier new, courier, monospace;\">Loader.exe<\/span>.<\/li>\n<li>The title of the argument accepting the 64-character-long password being named both <span style=\"font-family: courier new, courier, monospace;\">move<\/span> or <span style=\"font-family: courier new, courier, monospace;\">key<\/span>.<\/li>\n<\/ul>\n<h2>EDR killers on the rise<a rel=\"nofollow\" target=\"_blank\" id=\"EDR killers on the rise\"\/><\/h2>\n<p>EDRKillShifter shortly gained recognition amongst ransomware associates, and as we simply demonstrated, they don\u2019t use it completely in RansomHub intrusions. Nevertheless, it isn&#8217;t the one EDR killer on the market; in truth, ESET researchers have noticed a rise within the number of EDR killers utilized by ransomware associates.<\/p>\n<p>An EDR killer is malware designed to run in a compromised community, to blind, corrupt, crash, or terminate safety options defending the endpoints. The plain objective is to permit clean execution of the ransomware encryptor. Whereas extra immature ransomware associates settle with scripts that merely attempt to terminate an inventory of processes, extra subtle ones transcend that and use the method often called Convey Your Personal Susceptible Driver (BYOVD).<\/p>\n<p>EDR killers are an efficient and more and more in style addition to ransomware associates\u2019 arsenals. Throughout an intrusion, the objective of the affiliate is to acquire admin or area admin privileges. Ransomware operators have a tendency to not do main updates of their encryptors too usually because of the danger of introducing a flaw that might trigger points, in the end damaging their status. In consequence, safety distributors detect the encryptors fairly nicely, which the associates react to by utilizing EDR killers to \u201cdo away with\u201d the safety resolution simply earlier than executing the encryptor.<\/p>\n<h3>Anatomy of an EDR killer<\/h3>\n<p>Superior EDR killers encompass two components \u2013 a consumer mode part chargeable for orchestration (which we&#8217;ll confer with because the killer code) and a professional, however weak, driver. The execution is usually very simple \u2013 the killer code installs the weak driver, sometimes embedded in its information or assets, iterates over an inventory of course of names, and points a command to the weak driver, leading to triggering the vulnerability and killing the method from kernel mode.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 5. Anatomy of an EDR killer abusing a vulnerable driver\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2025\/03-25\/ransomhub\/figure-5.png\" alt=\"Figure 5. Anatomy of an EDR killer abusing a vulnerable driver\" width=\"\" height=\"\"\/><figcaption><em>Determine 5. Anatomy of an EDR killer abusing a weak driver<\/em><\/figcaption><\/figure>\n<h3>Few drivers, many killers<\/h3>\n<p>Sophos <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/news.sophos.com\/en-us\/2024\/08\/14\/edr-kill-shifter\/\" target=\"_blank\" rel=\"noopener\">documented<\/a> of their blogpost how totally different builds of EDRKillShifter abuse totally different weak drivers. One of many abused drivers, <span style=\"font-family: courier new, courier, monospace;\">rentdrv2.sys<\/span>, can be part of <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/github.com\/keowu\/BadRentdrv2\" target=\"_blank\" rel=\"noopener\">BadRentdrv2<\/a>, a publicly out there EDR killer. The second, TFSysMon from ThreatFire System Monitor, can be part of <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/github.com\/BlackSnufkin\/BYOVD\/tree\/main\/TfSysMon-Killer\">TFSysMon-Killer<\/a>, one other publicly out there PoC. The latter is a part of an even bigger assortment of 4 EDR killer PoCs written in Rust, which we&#8217;ve got noticed risk actors reimplement in C++ with out altering a single line of code.<\/p>\n<p>Whereas the <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.loldrivers.io\/\" target=\"_blank\" rel=\"noopener\">Dwelling Off The Land Drivers<\/a> mission offers over 1700 <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/github.com\/magicsword-io\/LOLDrivers\/tree\/main\/drivers\">weak drivers<\/a>, making them a profitable goal for cybercriminals, solely a handful of those drivers are abused by EDR killers \u2013 if there&#8217;s examined code abusing a vulnerability in one in all these drivers, it&#8217;s a lot simpler to reuse it with out having to design the code from scratch. Moreover, it permits the EDR killer builders to deal with the killer code and its stealthiness.<\/p>\n<h3>Grey zone of EDR killers<\/h3>\n<p>Reputable instruments are abused by ransomware associates to work as EDR killers, too. Such instruments, just like the <a rel=\"nofollow\" target=\"_blank\" href=\"http:\/\/www.gmer.net\/\" target=\"_blank\" rel=\"noopener\">GMER rootkit detector<\/a> and <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.fcportables.com\/pc-hunter-portable\/\">PC Hunter<\/a>, by their nature require entry to kernel mode and must carefully examine the internals of the working system. Sadly, additionally they provide a strong performance that may be abused when within the arms of malicious risk actors.<\/p>\n<h3>Including EDR killers to RaaS choices<\/h3>\n<p>RaaS applications usually don\u2019t present associates solely with encryptors \u2013 extra instruments and playbooks could also be a part of the package deal. As an illustration, LockBit provided <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\/aa23-075a\" target=\"_blank\" rel=\"noopener\">Stealbit<\/a>, a customized information exfiltration instrument, to its associates, and the <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/krebsonsecurity.com\/2022\/03\/conti-ransomware-group-diaries-part-i-evasion\/\" target=\"_blank\" rel=\"noopener\">Conti leaks<\/a> and <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/x.com\/vxunderground\/status\/1842456784067293544\" target=\"_blank\" rel=\"noopener\">Dispossessor leak<\/a> disclosed that playbooks, scripts, and know-how are additionally a part of the ransomware gangs\u2019 arsenal.<\/p>\n<p>Including an EDR killer to a RaaS providing appears logical, and RansomHub just isn&#8217;t the one gang doing that. In October 2024, ESET researchers <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.welivesecurity.com\/en\/eset-research\/embargo-ransomware-rocknrust\/\">documented<\/a> that the rising ransomware gang Embargo carried out its personal EDR killer as nicely, referred to as MS4Killer, by modifying a <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/github.com\/gavz\/s4killer\" target=\"_blank\" rel=\"noopener\">publicly out there PoC<\/a>. On the time of writing: whereas the group listed solely 14 victims on its DLS, it had already invested time and assets into growing its personal EDR killer.<\/p>\n<p>It stays to be seen whether or not EDR killers discover their place in additional gangs\u2019 choices. Nevertheless, this blogpost has additionally demonstrated that researchers could leverage their utilization to cluster associates and uncover new relationships between rival gangs.<\/p>\n<h3>Defeating EDR killers<\/h3>\n<p>Defending in opposition to EDR killers is difficult. Menace actors want admin privileges to deploy an EDR killer, so ideally, their presence needs to be detected and mitigated earlier than they attain that time.<\/p>\n<p>Whereas stopping the killer code from executing is the perfect method, code obfuscation could make this unreliable. Nevertheless, specializing in weak drivers offers extra protection choices. ESET considers drivers exploited by EDR killers probably unsafe. Subsequently, customers, particularly in company environments, ought to be certain that the detection of doubtless unsafe purposes is enabled. This may forestall the set up of weak drivers.<\/p>\n<p>Though not widespread, subtle risk actors could exploit a weak driver already current on a compromised machine as an alternative of counting on BYOVD. To counter this, having correct patch administration in place is an efficient and important protection technique.<\/p>\n<h2>Conclusion<\/h2>\n<p>The ransomware ecosystem suffered vital blows in 2024. Regardless of the general variety of recorded assaults growing, it shouldn&#8217;t overshadow the optimistic impact of efficiently disrupting or eliminating two ransomware gangs that had been dominating the scene for years.<\/p>\n<p>We are able to speculate about how a lot the results of legislation enforcement actions decreased ransomware funds, or how the rising consciousness and initiatives just like the <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.counter-ransomware.org\/\" target=\"_blank\" rel=\"noopener\">Counter Ransomware Initiative<\/a> are serving to ransomware victims perceive that paying the ransom might not be one of the simplest ways ahead.<\/p>\n<p>What is obvious, sadly, is {that a} new subtle ransomware group, RansomHub, emerged, used the correct ways to draw associates (lots of whom we consider transitioned from BlackCat and LockBit) in a brief interval, and was shortly capable of climb to the highest of the ladder. Within the foreseeable future, RansomHub will certainly attempt to stay among the many most lively RaaS gangs.<\/p>\n<p>Regulation-enforcement-led disruptions of RaaS operators have proved efficient, sowing mistrust within the RaaS ecosystem. Sadly, 2024 confirmed that associates are capable of regroup pretty shortly. In any case, they&#8217;ve sturdy monetary incentives to deploy encryptors to and exfiltrate delicate information from their targets. Though harder to perform than disruptions, eliminating probably the most lively associates from the image can be efficient as a result of it might forestall new RaaS operators from gaining energy as shortly as RansomHub did. We consider that specializing in the associates, particularly by monitoring down their hyperlinks between varied gangs \u2013 as demonstrated on this blogpost between RansomHub, Play, Medusa, and BianLian \u2013 will in the end result in identification of the associates and their removing from the sport.<\/p>\n<blockquote>\n<div><em>For any inquiries about our analysis revealed on WeLiveSecurity, please contact us at <a rel=\"nofollow\" target=\"_blank\" style=\"background-color: #f4f4f4;\" href=\"https:\/\/www.welivesecurity.com\/en\/eset-research\/shifting-sands-ransomhub-edrkillshifter\/mailto:threatintel@eset.com?utm_source=welivesecurity.com&amp;utm_medium=referral&amp;utm_campaign=autotagging&amp;utm_content=eset-research&amp;utm_term=en\">threatintel@eset.com<\/a>.\u00a0<\/em><\/div>\n<div><em>ESET Analysis gives non-public APT intelligence stories and information feeds. For any inquiries about this service, go to the <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.eset.com\/int\/business\/services\/threat-intelligence\/?utm_source=welivesecurity.com&amp;utm_medium=referral&amp;utm_campaign=wls-research&amp;utm_content=shifting-sands-ransomhub-edrkillshifter&amp;sfdccampaignid=7011n0000017htTAAQ\" target=\"_blank\" rel=\"noopener\">ESET Menace Intelligence<\/a> web page.<\/em><\/div>\n<\/blockquote>\n<h2>IoCs<\/h2>\n<p>A complete listing of indicators of compromise and samples could be present in <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/github.com\/eset\/malware-ioc\/tree\/master\/ransomhub\" target=\"_blank\" rel=\"noopener\">our GitHub repository<\/a>.<\/p>\n<h3>Recordsdata<\/h3>\n<h3><span style=\"font-size: medium; font-weight: 400;\"><\/p>\n<table border=\"1\" width=\"642\" cellspacing=\"0\" cellpadding=\"0\">\n<thead>\n<tr>\n<td width=\"179\"><strong>SHA-1<\/strong><\/td>\n<td width=\"142\"><strong>Filename<\/strong><\/td>\n<td width=\"132\"><strong>Detection<\/strong><\/td>\n<td width=\"189\"><strong>Description<\/strong><\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">97E13515263002809505<wbr\/>DC913B04B49AEB78B067<\/span><\/td>\n<td width=\"142\"><span style=\"font-family: courier new, courier, monospace;\">amd64.exe<\/span><\/td>\n<td width=\"132\">WinGo\/Kryptik.CV<\/td>\n<td width=\"189\">RansomHub encryptor.<\/td>\n<\/tr>\n<tr>\n<td width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">BF84712C5314DF2AA851<wbr\/>B8D4356EA51A9AD50257<\/span><\/td>\n<td width=\"142\"><span style=\"font-family: courier new, courier, monospace;\">Loader.exe<\/span><\/td>\n<td width=\"132\">Win64\/Agent.DVP<\/td>\n<td width=\"189\">EDRKillShifter.<\/td>\n<\/tr>\n<tr>\n<td width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">87D0F168F049BEFE455D<wbr\/>5B702852FFB7852E7DF6<\/span><\/td>\n<td width=\"142\"><span style=\"font-family: courier new, courier, monospace;\">amd64.exe<\/span><\/td>\n<td width=\"132\">WinGo\/Kryptik.CV<\/td>\n<td width=\"189\">RansomHub encryptor.<\/td>\n<\/tr>\n<tr>\n<td width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">2E89CF3267C8724002C3<wbr\/>C89BE90874A22812EFC6<\/span><\/td>\n<td width=\"142\"><span style=\"font-family: courier new, courier, monospace;\">Magic.exe<\/span><\/td>\n<td width=\"132\">Win64\/Agent.DVP<\/td>\n<td width=\"189\">EDRKillShifter.<\/td>\n<\/tr>\n<tr>\n<td width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">3B035DA6C69F9B05868F<wbr\/>FE55D7A267D098C6F290<\/span><\/td>\n<td width=\"142\"><span style=\"font-family: courier new, courier, monospace;\">TDSSKiller.exe<\/span><\/td>\n<td width=\"132\">Win32\/RiskWare.<wbr\/>TDSSKiller.A<\/td>\n<td width=\"189\">TDSSKiller.<\/td>\n<\/tr>\n<tr>\n<td width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">5ECAFF68D36EC1033742<wbr\/>8267D05CD3CB632C0444<\/span><\/td>\n<td width=\"142\"><span style=\"font-family: courier new, courier, monospace;\">svchost.exe<\/span><\/td>\n<td width=\"132\">WinGo\/HackTool.<wbr\/>Agent.EY<\/td>\n<td width=\"189\">Rclone.<\/td>\n<\/tr>\n<tr>\n<td width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">DCF711141D6033DF4C91<wbr\/>49930B0E1078C3B6D156<\/span><\/td>\n<td width=\"142\"><span style=\"font-family: courier new, courier, monospace;\">anydes.ps1<\/span><\/td>\n<td width=\"132\">PowerShell\/Agent.AEK<\/td>\n<td width=\"189\">Script that deploys and password protects AnyDesk.<\/td>\n<\/tr>\n<tr>\n<td width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">E38082AE727AEAEF4F24<wbr\/>1A1920150FDF6F149106<\/span><\/td>\n<td width=\"142\"><span style=\"font-family: courier new, courier, monospace;\">netscan.exe<\/span><\/td>\n<td width=\"132\">Win64\/NetTool.Comfortable<wbr\/>PerfectNetscan.A<\/td>\n<td width=\"189\">SoftPerfect Community Scanner.<\/td>\n<\/tr>\n<tr>\n<td width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">046583DEB4B418A6F1D8<wbr\/>DED8BED9886B7088F338<\/span><\/td>\n<td width=\"142\"><span style=\"font-family: courier new, courier, monospace;\">conhost.dll<\/span><\/td>\n<td width=\"132\">Win64\/Coroxy.J<\/td>\n<td width=\"189\">SystemBC.<\/td>\n<\/tr>\n<tr>\n<td width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">3B4AEDAFA9930C19EA88<wbr\/>9723861BF95253B0ED80<\/span><\/td>\n<td width=\"142\"><span style=\"font-family: courier new, courier, monospace;\">win64_1.exe<\/span><\/td>\n<td width=\"132\">Win64\/Agent.RA<\/td>\n<td width=\"189\">BianLian backdoor.<\/td>\n<\/tr>\n<tr>\n<td width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">460D7CB14FCED78C701E<wbr\/>7668C168CF07BCE94BA1<\/span><\/td>\n<td width=\"142\"><span style=\"font-family: courier new, courier, monospace;\">WKTools.exe<\/span><\/td>\n<td width=\"132\">Win32\/WKTools.A<\/td>\n<td width=\"189\">WKTools.<\/td>\n<\/tr>\n<tr>\n<td width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">5AF059C44D6AC8EF92AA<wbr\/>458C5ED77F68510F92CD<\/span><\/td>\n<td width=\"142\"><span style=\"font-family: courier new, courier, monospace;\">pfw.exe<\/span><\/td>\n<td width=\"132\">Win64\/Agent.RA<\/td>\n<td width=\"189\">BianLian backdoor.<\/td>\n<\/tr>\n<tr>\n<td width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">67D17CA90880B448D5C3<wbr\/>B40F69CEC04D3649F170<\/span><\/td>\n<td width=\"142\"><span style=\"font-family: courier new, courier, monospace;\">1721894530.sys<\/span><\/td>\n<td width=\"132\">Win64\/RentDrv.A<\/td>\n<td width=\"189\">Susceptible driver utilized by EDRKillShifter.<\/td>\n<\/tr>\n<tr>\n<td width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">77DAF77D9D2A08CC2298<wbr\/>1C004689B870F74544B5<\/span><\/td>\n<td width=\"142\"><span style=\"font-family: courier new, courier, monospace;\">Killer.exe<\/span><\/td>\n<td width=\"132\">Win64\/Agent.DVP<\/td>\n<td width=\"189\">EDRKillShifter.<\/td>\n<\/tr>\n<tr>\n<td width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">180D770C4A55C62C09AA<wbr\/>D1FC3412132D87AF5CF6<\/span><\/td>\n<td width=\"142\"><span style=\"font-family: courier new, courier, monospace;\">1.dll<\/span><\/td>\n<td width=\"132\">Win64\/Coroxy.Ok<\/td>\n<td width=\"189\">SystemBC.<\/td>\n<\/tr>\n<tr>\n<td width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">DD6FA8A7C1B3E009F5F1<wbr\/>7176252DE5ACABD0FB86<\/span><\/td>\n<td width=\"142\"><span style=\"font-family: courier new, courier, monospace;\">d.exe<\/span><\/td>\n<td width=\"132\">Win32\/Filecoder<wbr\/>.PLAY.B<\/td>\n<td width=\"189\">Play encryptor.<\/td>\n<\/tr>\n<tr>\n<td width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">FDA5AAC0C0DB36D173B8<wbr\/>8EC9DED8D5EF1727B3E2<\/span><\/td>\n<td width=\"142\"><span style=\"font-family: courier new, courier, monospace;\">GT_NET.exe<\/span><\/td>\n<td width=\"132\">MSIL\/Spy.Grixba.A<\/td>\n<td width=\"189\">Grixba.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><\/span><\/h3>\n<h3>Community<\/h3>\n<div><span style=\"font-size: medium; font-weight: 400;\"><\/p>\n<table border=\"1\" width=\"642\" cellspacing=\"0\" cellpadding=\"0\">\n<thead>\n<tr>\n<td width=\"151\"><strong>IP<\/strong><\/td>\n<td width=\"66\"><strong>Area<\/strong><\/td>\n<td width=\"170\"><strong>Internet hosting supplier<\/strong><\/td>\n<td width=\"85\"><strong>First seen<\/strong><\/td>\n<td width=\"170\"><strong>Particulars<\/strong><\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">45.32.206[.]169<\/span><\/td>\n<td width=\"66\">N\/A<\/td>\n<td width=\"170\">Vultr Holdings, LLC<\/td>\n<td width=\"85\">2024\u201107\u201125<\/td>\n<td width=\"170\">Server internet hosting WKTools and EDRKillShifter.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">45.32.210[.]151<\/span><\/td>\n<td width=\"66\">N\/A<\/td>\n<td width=\"170\">The Fixed Firm, LLC<\/td>\n<td width=\"85\">2024\u201108\u201109<\/td>\n<td width=\"170\">SystemBC C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">79.124.58[.]130<\/span><\/td>\n<td width=\"66\">N\/A<\/td>\n<td width=\"170\">TAMATYA-MNT<\/td>\n<td width=\"85\">2024\u201108\u201122<\/td>\n<td width=\"170\">Server internet hosting MeshAgent.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">92.243.64[.]200<\/span><\/td>\n<td width=\"66\">N\/A<\/td>\n<td width=\"170\">EDIS GmbH &#8211; Noc Engineer<\/td>\n<td width=\"85\">2024\u201107\u201125<\/td>\n<td width=\"170\">BianLian backdoor C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">130.185.75[.]198<\/span><\/td>\n<td width=\"66\">N\/A<\/td>\n<td width=\"170\">Pars Parva System LTD<\/td>\n<td width=\"85\">2024\u201108\u201120<\/td>\n<td width=\"170\">Server internet hosting PuTTY.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">149.154.158[.]222<\/span><\/td>\n<td width=\"66\">N\/A<\/td>\n<td width=\"170\">EDIS GmbH &#8211; Noc Engineer<\/td>\n<td width=\"85\">2024\u201107\u201125<\/td>\n<td width=\"170\">Server internet hosting BianLian backdoor.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><\/span><\/div>\n<h2>MITRE ATT&amp;CK strategies<\/h2>\n<p style=\"page-break-after: avoid;\"><em>This desk was constructed utilizing <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/resources\/versions\/\">model 16<\/a> of the MITRE ATT&amp;CK framework<strong>.<\/strong><\/em><\/p>\n<div><span style=\"font-size: medium; font-weight: 400;\"><\/p>\n<table border=\"1\" width=\"642\" cellspacing=\"0\" cellpadding=\"0\">\n<thead>\n<tr>\n<td width=\"113\"><strong>Tactic<\/strong><\/td>\n<td width=\"113\"><strong>ID<\/strong><\/td>\n<td width=\"151\"><strong>Identify<\/strong><\/td>\n<td width=\"265\"><strong>Description<\/strong><\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td rowspan=\"6\" width=\"113\"><strong>Useful resource Improvement<\/strong><\/td>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v16\/techniques\/T1583\">T1583<\/a><\/td>\n<td width=\"151\">Purchase Infrastructure<\/td>\n<td width=\"265\">QuadSwitcher acquired infrastructure to host their tooling.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v16\/techniques\/T1587\/001\">T1587.001<\/a><\/td>\n<td width=\"151\">Develop Capabilities: Malware<\/td>\n<td width=\"265\">The RansomHub, Play, Medusa, and BianLian gangs develop their very own encryptors and associated tooling.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v16\/techniques\/T1588\/001\">T1588.001<\/a><\/td>\n<td width=\"151\">Get hold of Capabilities: Malware<\/td>\n<td width=\"265\">The Play gang makes use of SystemBC, a commodity malware on the market.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v16\/techniques\/T1588\/002\">T1588.002<\/a><\/td>\n<td width=\"151\">Get hold of Capabilities: Device<\/td>\n<td width=\"265\">Numerous third-party instruments are often utilized by the gangs\u2019 associates.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v16\/techniques\/T1608\/001\">T1608.001<\/a><\/td>\n<td width=\"151\">Stage Capabilities: Add Malware<\/td>\n<td width=\"265\">The Play gang uploaded its personal tooling to a devoted server for use throughout intrusions.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v16\/techniques\/T1608\/002\">T1608.002<\/a><\/td>\n<td width=\"151\">Stage Capabilities: Add Device<\/td>\n<td width=\"265\">The Play gang uploaded the third-party instruments it makes use of to a devoted server for use throughout intrusions.<\/td>\n<\/tr>\n<tr>\n<td rowspan=\"2\" width=\"113\"><strong>Execution<\/strong><\/td>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v16\/techniques\/T1059\/001\">T1059.001<\/a><\/td>\n<td width=\"151\">Command-Line Interface: PowerShell<\/td>\n<td width=\"265\">QuadSwitcher deployed AnyDesk utilizing a PowerShell script.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v16\/techniques\/T1059\/003\">T1059.003<\/a><\/td>\n<td width=\"151\">Command-Line Interface: Home windows Command Shell<\/td>\n<td width=\"265\">Home windows Command Shell is often utilized by QuadSwitcher to challenge instructions.<\/td>\n<\/tr>\n<tr>\n<td rowspan=\"6\" width=\"113\"><strong>Protection Evasion<\/strong><\/td>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v16\/techniques\/T1078\">T1078<\/a><\/td>\n<td width=\"151\">Legitimate Accounts<\/td>\n<td width=\"265\">QuadSwitcher abuses extracted credentials of legitimate accounts to maneuver within the community stealthily.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v16\/techniques\/T1078\/002\">T1078.002<\/a><\/td>\n<td width=\"151\">Legitimate Accounts: Area Accounts<\/td>\n<td width=\"265\">QuadSwitcher in the end gained area admin privileges in among the intrusions.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v16\/techniques\/T1480\">T1480<\/a><\/td>\n<td width=\"151\">Execution Guardrails<\/td>\n<td width=\"265\">RansomHub\u2019s encryptor requires a password to run.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v16\/techniques\/T1562\/001\">T1562.001<\/a><\/td>\n<td width=\"151\">Impair Defenses: Disable or Modify Instruments<\/td>\n<td width=\"265\">EDRKillShifter\u2019s purpose is to disable safety options.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v16\/techniques\/T1562\/009\">T1562.009<\/a><\/td>\n<td width=\"151\">Impair Defenses: Secure Mode Boot<\/td>\n<td width=\"265\">RansomHub\u2019s encryptor permits rebooting to secure mode to encrypt recordsdata.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v16\/techniques\/T1218\">T1218<\/a><\/td>\n<td width=\"151\">System Binary Proxy Execution<\/td>\n<td width=\"265\">QuadSwitcher abused <span style=\"font-family: courier new, courier, monospace;\">certutil.exe<\/span> to obtain payloads.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><strong>Credential Entry<\/strong><\/td>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v16\/techniques\/T1110\">T1110<\/a><\/td>\n<td width=\"151\">Brute Power<\/td>\n<td width=\"265\">QuadSwitcher tried to brute pressure credentials in the course of the intrusions.<\/td>\n<\/tr>\n<tr>\n<td rowspan=\"2\" width=\"113\"><strong>Discovery<\/strong><\/td>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v16\/techniques\/T1087\">T1087<\/a><\/td>\n<td width=\"151\">Account Discovery<\/td>\n<td width=\"265\">With a view to elevate privileges, QuadSwitcher found extra accounts.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v16\/techniques\/T1057\">T1057<\/a><\/td>\n<td width=\"151\">Course of Discovery<\/td>\n<td width=\"265\">EDRKillShifter seems for particular processes associated to safety options.<\/td>\n<\/tr>\n<tr>\n<td rowspan=\"2\" width=\"113\"><strong>Lateral Motion<\/strong><\/td>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v16\/techniques\/T1021\/001\">T1021.001<\/a><\/td>\n<td width=\"151\">Distant Providers: Distant Desktop Protocol<\/td>\n<td width=\"265\">RDP was usually used for lateral motion within the compromised networks.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v16\/techniques\/T1021\/002\">T1021.002<\/a><\/td>\n<td width=\"151\">Distant Providers: SMB\/Home windows Admin Shares<\/td>\n<td width=\"265\">RansomHub helps distant encryption of recordsdata.<\/td>\n<\/tr>\n<tr>\n<td rowspan=\"2\" width=\"113\"><strong>Assortment<\/strong><\/td>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v16\/techniques\/T1005\">T1005<\/a><\/td>\n<td width=\"151\">Information from Native System<\/td>\n<td width=\"265\">The BianLian gang focuses on information exfiltration, gathering information from native drives.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v16\/techniques\/T1039\">T1039<\/a><\/td>\n<td width=\"151\">Information from Community Shared Drive<\/td>\n<td width=\"265\">The BianLian gang focuses on information exfiltration, gathering information from community drives.<\/td>\n<\/tr>\n<tr>\n<td rowspan=\"3\" width=\"113\"><strong>Command and Management<\/strong><\/td>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v16\/techniques\/T1071\">T1071<\/a><\/td>\n<td width=\"151\">Utility Layer Protocol<\/td>\n<td width=\"265\">In Play intrusions, payloads are retrieved through HTTP.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v16\/techniques\/T1132\/002\">T1132.002<\/a><\/td>\n<td width=\"151\">Information Encoding: Non-Normal Encoding<\/td>\n<td width=\"265\">SystemBC employs a customized community protocol.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v16\/techniques\/T1219\">T1219<\/a><\/td>\n<td width=\"151\">Distant Entry Software program<\/td>\n<td width=\"265\">A number of RMM instruments had been used, together with AnyDesk and MeshAgent.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><strong>Exfiltration<\/strong><\/td>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v16\/techniques\/T1537\">T1537<\/a><\/td>\n<td width=\"151\">Switch Information to Cloud Account<\/td>\n<td width=\"265\">BianLian associates used Rclone to exfiltrate information to a cloud account they management to keep away from typical file transfers\/downloads and network-based exfiltration detection.<\/td>\n<\/tr>\n<tr>\n<td rowspan=\"3\" width=\"113\"><strong>Impression<\/strong><\/td>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v16\/techniques\/T1485\">T1485<\/a><\/td>\n<td width=\"151\">Information Destruction<\/td>\n<td width=\"265\">Some information like backups could also be completely destroyed by ransomware gangs.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v16\/techniques\/T1486\">T1486<\/a><\/td>\n<td width=\"151\">Information Encrypted for Impression<\/td>\n<td width=\"265\">The final word results of ransomware gangs\u2019 actions is encryption of victims\u2019 information.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v16\/techniques\/T1657\">T1657<\/a><\/td>\n<td width=\"151\">Monetary Theft<\/td>\n<td width=\"265\">The ransomware gangs stress victims to pay ransom in change for regaining entry to their information.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><\/span><\/div>\n<p><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.eset.com\/int\/business\/services\/threat-intelligence\/?utm_source=welivesecurity.com&amp;utm_medium=referral&amp;utm_campaign=wls-research&amp;utm_content=shifting-sands-ransomhub-edrkillshifter&amp;sfdccampaignid=7011n0000017htTAAQ\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2023\/2023-12\/welivesecurity-eset-threat-intelligence.jpeg\" alt=\"\" width=\"915\" height=\"296\"\/><\/a><\/p>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>ESET researchers have a look again on the vital adjustments within the ransomware ecosystem in 2024 and deal with the newly emerged and at the moment dominating ransomware-as-a-service (RaaS) gang, RansomHub. We share beforehand unpublished insights into RansomHub\u2019s affiliate construction and uncover clear connections between this newly emerged large and well-established gangs Play, Medusa, and [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":4707,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[4136,4135,2253,4134],"class_list":["post-4705","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-edrkillshifter","tag-ransomhubs","tag-sands","tag-shifting"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/4705","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=4705"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/4705\/revisions"}],"predecessor-version":[{"id":4706,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/4705\/revisions\/4706"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/4707"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=4705"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=4705"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=4705"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-06-15 10:44:30 UTC -->