RansomHub’s malicious use of TDSSKiller to bypass endpoint detection and response (EDR)
Kaspersky Lab’s TDSSKiller is a widely used free utility for detecting and removing rootkits. However, a recent cyberattack campaign by the RansomHub ransomware gang has leveraged TDSSKiller to disable EDR systems, compromising their ability to detect and respond to malicious activity.Attack StrategyRansomHub’s attack strategy involves two tools:
Itagora tiene in archivio titolo e sommario per la ricerca interna. Il testo completo resta sulla fonte. Il link in uscita non invia referrer.