CyberSecurity SEE

Ransomware Groups Increasingly Use EDR Kill Techniques

Ransomware Groups Increasingly Use EDR Kill Techniques

In a striking analysis released by Halcyon, the cybersecurity landscape reveals a concerning trend: the shutdown of endpoint detection and response (EDR) tools prior to the initiation of encryption in ransomware attacks has become a routine practice among cybercriminals. This alarming strategy, commonly referred to as "EDR-kill," once reserved for a select few notorious groups, has now been widely adopted across the entire ransomware sphere. The implications are significant, as this shift allows attackers to operate with amplified stealth, dramatically reducing the timeframe that defenders have to identify and mitigate an ongoing compromise.

The findings were detailed in Halcyon’s recently published report, the Q2 2026 Ransomware Evolution Report, which was made public on July 27. This report offers a comprehensive overview of the evolving tactics employed by key ransomware groups, highlighting how some are now systematically incorporating EDR or antivirus shutdowns into their attack methodologies. Among these groups is The Gentlemen, a burgeoning force in the ransomware landscape, which has drawn particular attention due to its rapid rise and increasing number of attack claims.

As per insights from Halcyon’s Ransomware Research Center, The Gentlemen group has engaged in reverse-engineering the methodologies of established ransomware operators, including Babuk, Qilin, LockBit 5.0, and Medusa. This meticulous analysis has enabled them to adopt the most effective encryption techniques, code-obfuscation methods, and strategies for evading detection—a tactic that has significantly bolstered their operational effectiveness.

The data presented in Halcyon’s report indicates a total of 1,988 publicly reported ransomware incidents, attributed to 89 active groups targeting organizations in 101 countries during the second quarter of 2026. Despite a noticeable decline of 5.7% in the overall number of reported attacks compared to the previous quarter, the report underscores a corresponding shift towards increasingly sophisticated tactics employed by attackers. These developments suggest a rapid evolution towards operations that are not only automated but also considerably more challenging to detect.

Among the most active ransomware groups during this period were Qilin, which recorded 293 attack claims, The Gentlemen with 214 claims, followed by DragonForce (143 claims), Akira (119 claims), and Lockbit 5.0 (102 claims). Interestingly, while groups like DragonForce and LockBit 5.0 witnessed surges in activity, The Gentlemen managed to surpass Qilin to become the top group by the end of June.

Halcyon’s research further identified a number of emerging or re-emerging ransomware entities, including KryBit, Payload, PEAR, and World Leaks. The manufacturing sector emerged as the most targeted industry, accounting for nearly 20% of all reported cyber extortion attacks. Following manufacturing, the construction industry and business services sectors were also notably impacted, alongside retail and software industries.

The report also highlights specific vulnerabilities that ransomware groups exploited during this period, particularly in enterprise edge devices. Notable targets included Citrix NetScaler ADC and Gateway, SonicWall SSL VPN, and Fortinet’s FortiOS, underscoring the necessity for organizations to bolster their cybersecurity measures against these common points of compromise.

Notably, the speed at which certain groups, particularly DragonForce and Akira, transitioned from initial breaches to full-fledged ransomware deployment has dramatically decreased, with some operations occurring in under an hour. This alarming acceleration of processes poses a severe challenge to traditional cybersecurity defenses, emphasizing the need for more adaptive and resilient strategies.

Moreover, the report indicates that artificial intelligence (AI) is transitioning from a theoretical concept to an integral component of ransomware operations. The utilization of AI extends throughout the attack lifecycle, encompassing malware disguised as AI productivity tools and AI-assisted negotiations with victims. Halcyon noted the emergence of an “agentic” ransomware capable of autonomously executing stages of an attack, such as gaining initial access to systems.

Ross Asquith, the solutions engineering director for Europe at Halcyon, pointed out that the democratization of EDR-kill tactics, along with the increasing reliance on AI in ransomware operations, signifies a shift where the ransomware ecosystem has become more efficient at circumventing security infrastructures. He urged cybersecurity professionals to prioritize resilience, cautioning that reliance on conventional controls may no longer provide adequate time for effective responses.

As the report concluded, it also illuminated the growing intertwining of ransomware and state-sponsored objectives, with actors linked to Iranian interests increasingly camouflaging espionage activities within the guise of criminal ransomware operations. This intersection raises significant concerns for national security and the broader cybersecurity landscape, highlighting the urgent need for robust measures to confront these evolving threats.

Source link

Exit mobile version