Skip to content

Hide Navigation Hide TOC

EDRKillShifter (1233436f-2a00-4557-89a4-8cbc45e6f9f7)

EDRKillShifter is a suspected threat actor-developed tool that is designed to disable victim endpoint detection & response (EDR) software. In August 2024, security researchers reported that the RansomHub ransomware group had deployed EDRKillShifter during attacks in May. The researchers also noted that EDRKillShifter primarily functions as a loader for payloads that could vary. This object mainly reflects ATT&CK Techniques associated with observed EDRKillShifter loader and payload deployments reported in August 2024.[Sophos News August 14 2024]

Cluster A Galaxy A Cluster B Galaxy B Level
EDRKillShifter (1233436f-2a00-4557-89a4-8cbc45e6f9f7) Tidal Software CosmicBeetle (04b73cf2-33f4-4206-be9e-c80c4c9b54e8) Tidal Groups 1
EDRKillShifter (1233436f-2a00-4557-89a4-8cbc45e6f9f7) Tidal Software RansomHub Ransomware Actors (94794e7b-8b54-4be8-885a-fd1009425ed5) Tidal Groups 1