Skip to main content

Threats Tagged 'edr evasion'

View all threats tagged with 'edr evasion'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: edr evasion

Threats Tagged 'edr evasion'

Click on any threat for detailed analysis and mitigation recommendations

In July 2026, IIJ discovered and analyzed an unknown .NET-based malicious tool hosted on a public directory. This tool, named PIVOTPIPE, exhibits functionality similar to Cobalt Strike Beacon, communicating with C2 servers using configurations close to default profiles and supporting numerous C2 commands. However, PIVOTPIPE differs from official Cobalt Strike Beacon through unique implementations including detection evasion code, custom loaders, and obfuscated strings. The tool consists of two components: a loader and RAT module. The loader implements AMSI bypass, indirect syscalls, and sleep masking for EDR evasion. PIVOTPIPE supports TCP Beacon and SMB Beacon functionality for peer-to-peer communication through compromised hosts. Debug artifacts suggest the tool was still under development at the time of discovery, indicating potential future enhancements.

Join the discussion

An Akira ransomware affiliate gained initial access through an exposed SonicWall VPN without multi-factor authentication via credential spraying. After compromising the domain controller, the attacker performed Active Directory enumeration, collected and exfiltrated data using WinRAR and s5cmd to cloud storage. The affiliate employed a novel evasion technique by rebooting the victim host into Safe Mode with Networking to disable EDR and antivirus protection. AnyDesk was installed as a persistent remote access mechanism. However, the Safe Mode environment caused the ransomware to fail due to out-of-virtual-memory errors, preventing encryption. Despite the encryption failure, the attacker had already exfiltrated credentials and file shares, enabling extortion through data leak threats. This marks the first observed instance of Akira affiliates using Safe Mode boot as an anti-EDR technique.

Join the discussion

A sophisticated multi-stage campaign targets government entities in the Middle East, deploying BINDCLOAK, a previously undocumented 64-bit modular Windows backdoor written in C++. BINDCLOAK is decrypted and reflectively loaded by MIXEDKEY loader as part of a complex attack chain. The backdoor employs advanced techniques including a complex message routing mechanism for C2 communications, EDR evasion to prevent detection of API calls from unbacked executable memory regions, and token manipulation for privilege escalation. Code similarities and shared infrastructure directly connect this activity to the OctLurk backdoor, representing an expansion from Central Asia operations to Middle East targeting with focus on energy sector. The threat actor demonstrates sophisticated development capabilities through custom encryption, modular plugin architecture, and careful operational security measures.

Join the discussion
0

In February 2025, BlackBasta ransomware operations ceased after their internal chat logs were leaked online, leading to disbandment. However, former affiliates continued launching attacks using different ransomware families, including the relatively unknown Payouts King group that emerged in April 2025. ThreatLabz has observed continued ransomware activity consistent with former BlackBasta initial access brokers since early 2026, utilizing similar tactics including spam bombing, Microsoft Teams phishing, and Quick Assist abuse. Payouts King implements sophisticated evasion techniques including stack-based string obfuscation, API hashing, and direct system calls to terminate security processes. The ransomware leverages 4,096-bit RSA and 256-bit AES counter mode encryption, selectively encrypting files while targeting security software and employing anti-forensics techniques like shadow copy deletion and event log clearing.

Join the discussion

A large-scale malvertising campaign targeting U.S.tax form searchers has been uncovered. The attack chain begins with Google Ads, using dual commercial cloaking services to evade detection. Victims are directed to rogue ScreenConnect installers, leading to a multi-stage crypter that ultimately deploys a BYOVD (Bring Your Own Vulnerable Driver) tool. This tool, named HwAudKiller, exploits a previously undocumented Huawei audio driver to terminate antivirus and EDR processes from kernel mode. The campaign's sophistication lies in its use of commodity tools and services, combining free-tier ScreenConnect instances, off-the-shelf crypters, and a signed driver with an exploitable weakness. The attackers consistently deploy multiple remote access tools on compromised hosts for redundancy, indicating a likely pre-ransomware or initial access broker operation.

Join the discussion
0

The DeadLock ransomware campaign employs a new Bring Your Own Vulnerable Driver (BYOVD) loader exploiting CVE-2024-51324, a vulnerability in Baidu Antivirus driver, to evade endpoint detection and response (EDR) tools. Attackers use PowerShell scripts to bypass User Account Control (UAC), disable Windows Defender, terminate security services, and delete volume shadow copies, facilitating ransomware deployment. DeadLock ransomware targets Windows systems with a custom stream cipher encryption using time-based cryptographic keys, employing advanced techniques such as recursive directory traversal, memory-mapped file I/O, and multi-threaded processing. Initial access is gained through compromised accounts, followed by system registry modifications, remote access establishment, reconnaissance, lateral movement, and defense impairment. Although no known exploits are currently in the wild, the sophisticated use of BYOVD and defense evasion techniques poses a significant threat to organizations. The attack complexity and multi-stage process highlight the need for targeted mitigation strategies. This threat is particularly relevant to European organizations using Baidu Antivirus or similar vulnerable drivers and those with Windows-based infrastructure. The suggested severity is high due to the potential for widespread impact, ease of defense evasion, and the ransomware’s destructive capabilities.

Join the discussion

Check Point Research uncovered an ongoing campaign by the Silver Fox APT group exploiting a previously unknown vulnerable driver to evade endpoint protection. The attackers used a Microsoft-signed WatchDog Antimalware driver to terminate protected processes on fully updated Windows systems. A dual-driver strategy ensured compatibility across Windows versions. Following disclosure, the vendor released a patched driver, but attackers quickly adapted by modifying it to bypass blocklists while preserving its valid signature. The campaign delivered ValleyRAT as the final payload, demonstrating sophisticated evasion techniques and highlighting the growing trend of weaponizing signed-but-vulnerable drivers to bypass security measures.

Join the discussion

Showing 1 to 7 of 7 results

Filters:Tag: edr evasion
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses