Advertisement
UAT-10147 Leverages Agentic AI for EDR-Evasive Cybercrime
Talos details UAT-10147, an AI-driven cybercrime group orchestrating sophisticated post-compromise operations and evading EDR with custom rootkits.
Windows Bind Link Evasion: How to Detect Malware Hiding from EDR
Bitdefender researchers reveal how Windows bind links create filesystem discrepancies to bypass security tools. Learn how to mitigate this evasion technique.
GodDamn Ransomware Leverages Signed Driver to Disable EDR
Analysis of GodDamn ransomware's BYOVD technique, utilizing a Microsoft co-signed driver to disable security software, impacting US companies.
Gentlemen Ransomware: EDR Evasion Tactics and Mitigation Strategies
Runtime Rebel details Gentlemen ransomware's advanced EDR killer suite, analyzing its impact and providing actionable strategies to defend against sophisticated evasion.
Attackers Automate EDR Evasion Testing with Python Scripts
Attackers are automating EDR evasion testing using Python scripts against major platforms like Sophos, CrowdStrike, and Windows Defender, challenging defenses.
AI-Built Ransomware Toolkit Automates EDR Evasion, AD Discovery
New AI-powered ransomware toolkit automates Active Directory discovery and EDR evasion, posing advanced threats. Learn its capabilities and mitigation strategies.
Advertisement
Malware Evolution: How New Libraries and Languages Bypass EDR
Attackers are adopting Go, Rust, and custom libraries to evade static signatures. Learn how to adapt your detection engineering for modern malware binaries.
Payouts King Ransomware Deploys QEMU VMs to Evade EDR Solutions
Payouts King ransomware leverages QEMU virtualization and reverse SSH tunnels to bypass endpoint security and encrypt MSSQL servers on corporate networks.
Warlock Ransomware: BYOVD Techniques and Post-Exploitation Analysis
The Warlock ransomware group has evolved its tactics, utilizing BYOVD techniques and stealthy cross-network activity to bypass EDR and security controls.
Hypervisor-Based Persistence: Abusing Virtual Machines for Stealth
Analysis of how threat actors leverage virtualization platforms to host malicious guest OSs, bypassing host-level EDR and maintaining persistent access.