Thursday, September 19, 2024
Home Tech & Gadgets Kaspersky security tools hijacked to disable online security systems

Kaspersky security tools hijacked to disable online security systems

by Jeffrey Beilley
0 comments

Infamous ransomware group RansomHub has been caught abusing a legitimate Kaspersky tool to disable Endpoint Detection and Response (EDR) tools and then install stage two malware on infected systems without detection.

Cybersecurity researchers Malwarebytes, who recently spotted the activity in the wild, noted that once RansomHub compromises an endpoint and finds a way to get in, it must first disable any EDR tools before deploying infostealers or encryptors. In this scenario, the tool they used is called TDSSKiller – Kspersky’s specialized tool designed to detect and remove rootkits, specifically those from the TDSS family (also known as TDL4).

You may also like

Leave a Comment

Soledad is the Best Newspaper and Magazine WordPress Theme with tons of options and demos ready to import. This theme is perfect for blogs and excellent for online stores, news, magazine or review sites.

Buy Soledad now!

Edtior's Picks

Latest Articles

u00a92022u00a0Soledad.u00a0All Right Reserved. Designed and Developed byu00a0Penci Design.