ZeroHour
Infosecurity Magazinepublished ()ingested Kevin Poireault

Ransomware Groups Increasingly Deploy EDR Kill Techniques

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-40766
Improper Access Control in SonicWall SonicOS Management (Gen 5/6/7 Firewalls)

CVE-2024-40766 is an improper access control flaw (CWE-284) in SonicWall SonicOS management access that can allow unauthorized access to protected resources and, under specific conditions, crash the affected firewall. It is network-exploitable without privileges or user interaction per its CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N) and affects Gen 5 and Gen 6 appliances as well as Gen 7 devices running SonicOS 7.0.1-5035 or older. A successful attacker gains unauthorized access to resources behind or on the appliance and can potentially take the firewall offline, creating opportunities for follow-on attacks such as VPN account compromise and ransomware deployment. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-09-09 with known ransomware use, and recent reporting ties Akira ransomware activity — including MFA bypass on SonicWall VPNs affecting over 100 accounts — to this legacy bug combined with password reuse. No public PoC is known, but EPSS assigns an ~18.2% probability of exploitation within 30 days (97th percentile).

Do: Upgrade Gen 7 appliances to SonicOS 7.0.1-5037 or later (the fixed release beyond the affected 7.0.1-5035) and move Gen 5/6 devices to the latest SonicOS release SonicWall supports for those generations; per CISA KEV guidance, apply vendor mitigations or discontinue use if patching is not possible. Restrict WAN-side management and SSLVPN access to trusted sources, audit VPN accounts for password reuse, rotate credentials and any locally stored recovery codes, and review logs for signs of Akira-related compromise such as MFA bypass or disabled EDR agents.

9.818% KEV ransomware
  • SonicWall SonicOS (Gen 5 firewalls) Gen 5 appliances, all versions per the CISA advisory
  • SonicWall SonicOS (Gen 6 firewalls) Gen 6 appliances, all versions per the CISA advisory
  • SonicWall SonicOS (Gen 7 firewalls) SonicOS 7.0.1-5035 and older
mass≈100,000–500,000 internet-exposed SonicWall firewalls/SSLVPN endpoints (installed base of 1M+ appliances)
CVE-2024-55591
Unauthenticated Super-Admin Bypass in Fortinet FortiOS and FortiProxy

CVE-2024-55591 is an authentication bypass (CWE-288) in the Node.js websocket module of Fortinet FortiOS and FortiProxy that lets a remote, unauthenticated attacker gain super-admin privileges via crafted websocket requests. It affects FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12, and is trivially triggerable from the network with no user interaction given network access to the management/websocket interface. Successful exploitation gives full super-admin control of the appliance, which attackers can use to pivot, create persistent access, and deploy ransomware. Any organization running the affected FortiOS or FortiProxy versions, especially with admin interfaces reachable from the internet, is affected. Exploitation is confirmed in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-01-14, and multiple ransomware crews (reported as Gunra, SuperBlack, and Mora_001) are actively exploiting it.

Do: Upgrade all affected systems beyond the vulnerable ranges — FortiOS later than 7.0.16 and FortiProxy later than 7.0.19 / 7.2.12 — following Fortinet's advisory, or apply the vendor's mitigations where upgrades are not possible (per CISA KEV instructions). Restrict access to the admin/websocket interface from the internet, and hunt for unauthorized super-admin accounts and suspicious websocket connections, since ransomware operators are actively exploiting this flaw. Verify device versions and audit logs for signs of compromise before and after patching.

9.898% KEV ransomware
  • Fortinet FortiOS 7.0.0 through 7.0.16
  • Fortinet FortiProxy 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12
large≈48,000+ internet-exposed Fortinet devices per public scans, out of an installed base in the hundreds of thousands
CVE-2025-5777
Out-of-Bounds Read (Memory Overread) in Citrix NetScaler ADC and Gateway

Citrix NetScaler ADC and NetScaler Gateway contain an out-of-bounds read (CWE-125) caused by insufficient input validation, which can cause the appliance to read beyond the intended memory buffer (a memory overread). The flaw is only triggerable when the appliance is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, or RDP Proxy) or as an AAA virtual server, so attackers who can reach those services can potentially induce the overread and obtain sensitive memory contents. Such disclosure could aid follow-on compromise, for example by exposing session or authentication data, and CISA notes known ransomware use. Organizations running NetScaler ADC or NetScaler Gateway in the affected Gateway/AAA configurations are exposed. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2025-07-10 with known ransomware use and an EPSS of 100% (100th percentile), indicating active exploitation, while no public PoC is known and a CVSS score has not yet been assigned.

Do: Apply the fixed NetScaler ADC/Gateway builds per Citrix's security advisory (exact affected/fixed version ranges are not in the available data, so consult the bulletin); per CISA KEV, apply vendor mitigations, follow BOD 22-01 guidance for cloud services, or discontinue use if mitigations are unavailable. Inventory appliances for Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server configurations, since unconfigured/other deployments are not triggerable. After patching, terminate active and idle VPN sessions and hunt for anomalous access, given the known ransomware exploitation and the information-disclosure nature of the flaw.

9.3100% KEV ransomware
  • Citrix NetScaler ADC
  • Citrix NetScaler Gateway
massplausibly hundreds of thousands of installed/internet-exposed NetScaler ADC and Gateway appliances (public scans have historically shown on the order of…
Full article589 words · extracted from infosecurity-magazine.com · click to collapse

Shutting down endpoint detection and response (EDR) tools before encryption begins has become standard operating procedure across the ransomware ecosystem, analysis of attacks by researchers at Halcyon has warned.

The practice, sometimes called EDR-kill, was once considered a specialist capability. It has now become standard practice among leading ransomware groups, giving defenders even less time to detect and contain attacks, said Halcyon in its Q2 2026 Ransomware Evolution Report, published on July 27.

Moreover, some of these leading ransomware groups are now including an EDR or antivirus shutdown into their attack chain.

This is the case with The Gentlemen, a group which has recently emerged and become one of the most prolific ransomware threats, which Halcyon has analyzed in detail.

In a previous threat assessment document, the company’s Ransomware Research Center shared that The Gentlemen’s developers are systematically reverse-engineering samples from other groups, such as Babuk, Qilin, LockBit 5.0 and Medusa, to select the strongest encryption routines, code-obfuscation techniques and EDR evasion methods to incorporate into their own codebase.

Ransomware Attacks Decline, But Threats Grow More Sophisticated

Halcyon's ransomware report recorded 1988 publicly claimed ransomware attacks from 89 active groups targeting organizations across 101 countries during the second quarter of 2026.

While overall number of claimed attacks fell by 5.7% quarter on quarter, the underlying tactics used by attackers became significantly more advanced, “signalling a shift towards faster, more automated and harder-to-detect operations,” the company said.

The leading ransomware groups were Qilin (293 attack claims), The Gentlemen (214 attack claims, DragonForce (143 attack claims), Akira (119 attack claims) and Lockbit 5.0 (102 attack claims).

DragonForce and LockBit 5.0 showed an activity uptake in the second quarter of 2026, while The Gentlemen overtook Qilin for the top spot in June.

Halcyon also identified several emerging – or for some, returning – ransomware groups, including KryBit, Payload, PEAR and World Leaks.

Manufacturing was the industry most targeted by ransomware groups in Q2 2026, representing 19.8% of all cyber extortion attacks. Construction took the second place, followed by business services, retail and software.

Vulnerabilities in enterprise edge devices, such as in Citrix NetScaler ADC and Gateway (CVE-2025-5777), SonicWall SSL VPN (CVE-2024-40766) and Fortinet’s FortiOS (CVE-2024-55591) were among the most exploited by ransomware groups during the reported period.

The report noted groups like DragonForce and Akira moved from initial breach to ransomware deployment in under an hour in some attacks.

Ransomware Groups Operationalize AI

The Halcyon report found that for ransomware operations, AI is moving beyond experimentation into operational use.

“Threat actors increasingly leveraged AI throughout the attack chain, from malware disguised as AI productivity tools to AI-assisted victim negotiations and the emergence of what researchers believe to be the first agentic ransomware capable of autonomously conducting key stages of an intrusion,” the Halcyon analysts wrote.

For instance, Halcyon reported increased instances of the LLM-developed EvilAI masquerading as fake AI-productivity apps while secretly providing ransomware actors initial access.

Ross Asquith, solutions engineering director for Europe at Halcyon, said the democratization of EDR-kill techniques and the generalization of the use of AI in ransomware attack chains show that the “ransomware ecosystem is becoming faster, more automated and far more effective at neutralizing the security tools organizations rely on.”

This, he added, should prompt cyber defenders to focus on cyber resilience and “no longer assume traditional controls will buy them the time they need to respond.”

Finally, the report highlighted growing evidence of ransomware being used to support state objectives, with Iran-linked actors increasingly disguising espionage campaigns as criminal ransomware operations.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/ransomware-q2-2026-edr-kill/