Bring Your Own Vulnerable Device: The EDR Killer Economy
Cybersecurity Classified by Officially
Bring your own vulnerable driver (BYOVD) is having a moment in endpoint security. Some of the buzz is earned. Some of it is overblown. This series unpacks both and shows the evidence for each. This piece looks at the market that grew up around the technique.
A ransomware crew now ships an in-house “EDR killer” to its affiliates the way a product team ships software. It maintains the codebase. It versions the variants. It hands the tooling to paying partners with a support model behind it. The kill is no longer an improvised step in an intrusion. It is a product, and someone is on call for it.
That shift matters because it changes who you are actually fighting. Defenders have spent years treating the EDR killer as a lone operator's trick. The picture was a one-off binary, smuggled in by whoever read the right blog post. The current evidence points somewhere harder. EDR killing has become a service economy with pricing, affiliates, and operator-led R&D.
The clearest case is a ransomware-as-a-service (RaaS) operation tracked under the operator alias "hastalamuerte". Public threat reporting describes a crew that emerged in late 2025. It reached the top five ransomware gangs by the first quarter of 2026. Its flagship is an EDR killer framework that researchers describe as a shared development template. The operators build it. The affiliates use it.
Look at the build, and the word “framework” is earned. Researchers tracking the crew count eight or more variants in the kit. Each variant maps to a specific vulnerable driver, including ones from NSecsoft, Zemana, Qihoo 360, and Safetica. Each impersonates a legitimate security product to blend in. Together the variants hunt more than 400 processes across roughly 48 security products. They abuse kernel access to terminate the agents that should be watching.
This is an extract. The publication continues at the source.
Read the original at the source: https://www.sentinelone.com/blog/bring-your-own-vulnerable-device-the-edr-killer-economy/
Officially imported this from SentinelOne’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- SentinelOne — imported from official source
- Official source
- https://www.sentinelone.com/blog/feed/ RSS
- Imported
- October 02, 2026 16:00
- Versions
- 1 recorded
- Identity
blt17567964d3d32d3d