Ransomware Groups Deploy EDR Kill Techniques, Increasing Threats to Cybersecurity
Ransomware groups are increasingly employing techniques to shut down endpoint detection and response (EDR) tools before initiating encryption, according to a report by Halcyon. This practice, known as EDR-kill, has become standard among leading ransomware groups, reducing the time defenders have to detect and contain attacks. The report highlights the activities of The Gentlemen, a prolific ransomware group that reverse-engineers samples from other groups to enhance their attack methods. Despite a decline in the number of attacks, the sophistication of tactics has increased, with AI being operationalized in attack chains. Manufacturing remains the most targeted industry, followed by construction and business services.