A new analysis of EDR Killers (endpoint detection and response) programs has revealed that 54 of them leverage a technique known as “bring your own vulnerable driver ” (BYOVD) exploiting a total of 34 vulnerable drivers.
See also: XMRig Wormable Campaign: New attack with BYOVD exploit

EDR Killer programs are often present in ransomware attacks, as they provide a way for affiliates to neutralize security software before deploying malicious file‑encryption software. This is done in an attempt to avoid detection.
“ Ransomware gangs, especially those with ransomware-as-a-service (RaaS) programs, frequently produce new versions of their cryptographers, and ensuring that each version is reliably undetectable can be time-consuming ,” said ESET researcher Jakub Souček .
EDR Killers operate as a specialized, external component that runs to disable security checks before executing their lockers, thus keeping the latter simple, stable, and easy to rebuild. There have been cases where the EDR Killer and ransomware modules have been merged into a single binary, as seen with the Reynolds.
The majority of EDR Killers rely on legitimate but vulnerable drivers to gain elevated privileges and achieve their objectives. Among the nearly 90 EDR neutralization tools detected by the Slovak cybersecurity company, more than half use the well-known BYOVD tactic simply because it is reliable.
See also: SolarWinds Serv-U: Critical vulnerabilities allow root access

Armed with kernel access, malicious actors can terminate EDR processes, disable security tools, tamper with kernel callbacks, and undermine endpoint protections. This results in the abuse of Microsoft's driver trust model to evade defense, exploiting the fact that the vulnerable driver is legitimate and signed.
EDR Killers based on BYOVD are primarily developed by three types of malicious actors:
- 1. Closed ransomware groups such as DeadLock and Warlock that do not rely on partners.
- 2. Attackers who modify and adapt existing proof-of-concept code (e.g., SmilingKiller and TfSysMon-Killer).
- 3. Cybercriminals who sell such tools on underground markets as a service (e.g., DemoKiller, ABYSSWORKER and CardSpaceKiller).
ESET also identified script-based tools that use built-in administrative commands such as taskkill, net stop or sc delete to interfere with the normal operation of security product processes and services. Some variants combine scripts with Windows Safe Mode.
See also: Attackers exploit old Windows vulnerability to disable EDR

The third category of EDR Killers is anti-rootkits, which include legitimate tools such as GMER, HRSword , and PC Hunter, which offer an intuitive user interface for terminating protected processes or services. A fourth, emerging category is a set of driverless EDR Killers such as EDRSilencer and EDR-Freeze that block outgoing traffic from EDR solutions and cause programs to enter a “party” state.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
