HomeSecurityRansomHub: Uses Kaspersky's TDSSKiller to disable EDR solutions

RansomHub: Uses Kaspersky's TDSSKiller to disable EDR solutions

Malwarebytes security researchers have observed that the RansomHub ransomware group uses Kaspersky's TDSSKiller tool in its attacks to disable endpoint detection and response (EDR) systems.

RansomHub ransomware TDSSKiller Kaspersky

TDSSKiller is a legitimate tool developed by Kaspersky to remove rootkits. However, the software could also disable EDR solutions via a command line script or batch file.

Additionally, the ransomware group used the LaZagne to collect credentials.

See also: Hazard Ransomware: The story of a failed decryption

“ Both TDSSKiller and LaZagne have been used by attackers over the years, but this is the first time we see RansomHub using them in its operations ,” Malwarebytes says . “ The tools were developed after initial reconnaissance and network investigation via admin group enumeration .”

TDSSKiller

The RansomHub ransomware group used Kaspersky's TDSSKiller with the -dcsvc flagto attempt to disable critical security, specifically targeting the Malwarebytes Anti-Malware Service (MBAMService).

Command line: tdsskiller.exe -dcsvc MBAMService (In this case, the attackers tried to disable MBAMService).

RansomHub ransomware

This relatively new ransomware-as-a-service (RaaS) operation launched in February and demands money from victims in exchange for not leaking stolen files. If negotiations fail, it holds an auction and sells the documents to the highest bidder. The group focuses primarily on extortion based on data theft and less on encrypting victims’ files.

See also: NoName ransomware: “Collaboration” with the RansomHub group?

The malware targets multiple platforms, including Windows, Linux, macOS, ESXi, and Android.

RansomHub: Uses Kaspersky's TDSSKiller to disable EDR solutions

Legitimate programs are used by hackers

This is not the first time that experts have observed hackers using Kaspersky's TDSSKiller. In addition to RansomHub, the LockBit had also used the -dcsvc parameter of TDSSKiller as part of its attack chain.

Attackers are exploiting legitimate tools in their attacks because they are not blocked by security solutions. Therefore, it is important for organizations to regularly update their security measures and stay informed about the latest threatsin order to effectively protect themselves from ransomware attacks. This includes implementing multi-layered security solutions, educating employees on cybersecurity best practices, and conducting regular risk assessments.

See also: SonicWall: Critical vulnerability exploited by ransomware gangs

Additionally, it is important for organizations to have a solid incident response plan in the event of attack . This should include steps to contain and mitigate the attack, as well as procedures for recovering data from backups.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Source: securityaffairs.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS