Skip to main content
BYOVD_series.jpg
Company

Bring Your Own Vulnerable Device: The EDR Killer Economy

Door Matt Berry

Bring your own vulnerable driver (BYOVD) is having a moment in endpoint security. Some of the buzz is earned. Some of it is overblown. This series unpacks both and shows the evidence for each. This piece looks at the market that grew up around the technique.

A ransomware crew now ships an in-house “EDR killer” to its affiliates the way a product team ships software. It maintains the codebase. It versions the variants. It hands the tooling to paying partners with a support model behind it. The kill is no longer an improvised step in an intrusion. It is a product, and someone is on call for it.

That shift matters because it changes who you are actually fighting. Defenders have spent years treating the EDR killer as a lone operator's trick. The picture was a one-off binary, smuggled in by whoever read the right blog post. The current evidence points somewhere harder. EDR killing has become a service economy with pricing, affiliates, and operator-led R&D.

The clearest case is a ransomware-as-a-service (RaaS) operation tracked under the operator alias "hastalamuerte". Public threat reporting describes a crew that emerged in late 2025. It reached the top five ransomware gangs by the first quarter of 2026. Its flagship is an EDR killer framework that researchers describe as a shared development template. The operators build it. The affiliates use it.

Look at the build, and the word “framework” is earned. Researchers tracking the crew count eight or more variants in the kit. Each variant maps to a specific vulnerable driver, including ones from NSecsoft, Zemana, Qihoo 360, and Safetica. Each impersonates a legitimate security product to blend in. Together the variants hunt more than 400 processes across roughly 48 security products. They abuse kernel access to terminate the agents that should be watching.

The impersonation detail is the tell. Investigators found that each variant dresses up as a different legitimate security product, matching the driver it abuses. That is a product decision, made so the kill survives longer on more configurations. A lone operator does not build for portability across 48 defenders. A supplier with paying customers does, because portability is what the customers are buying.

The driver coverage reads like a compatibility matrix. The same reporting maps individual variants to drivers from NSecsoft, Zemana, Qihoo 360, and Safetica. Each loads through standard kernel control calls. A vendor supports many file formats so the product works on more customer machines. This crew supports many drivers so the kill works against more deployed defenders. The engineering intent is the same. Maximize the install base the tool can operate on.

This is a product line with coverage targets. The same crew also ships third-party killers alongside its own. Public reporting names HexKiller, ThrottleBlood, and HavocKiller carried in the same suite. It bundles a credential stealer called OxideHarvest as well. The kit is curated like a catalog.

A Catalog with Prices

Step back from one crew and the market comes into focus. Public threat research catalogs a large and growing population of EDR killers in circulation. That is not a handful of clever binaries. It is an inventory, large enough to support specialization, resale, and competition between sellers.

The scale sits underneath, in the drivers these tools abuse. Public threat research catalogs thousands of vulnerable signed drivers, most reachable without admin rights. A live tracking project keeps the running count of these drivers public. Cisco Talos found a single Qilin-linked killer that targets over 300 different EDR drivers in one tool. The raw material for this market is enormous, and most of it loads without elevated access.

Several of those tools carry price tags. SentinelLABS documented the Terminator EDR killer in 2023, sold by an actor known as Spyboy. The tool went for $300 to $3,000 and abused Zemana drivers. Priced tooling has a longer history here than most defenders assume. The kill has had a list price for years. What changed is the size of the shelf.

The strongest evidence sits in a SentinelLABS investigation of FIN7. The crew built an EDR killer called AvNeutralizer, also known as AuKill. It abused TTD and Process Explorer drivers to neutralize protected processes. FIN7 then sold it on Russian forums for $4,000 to $15,000. The same tool was adopted by Black Basta, AvosLocker, MedusaLocker, BlackCat, Trigona, and LockBit.

That resale pattern is the whole thesis in one artifact. One crew built the capability, then rented it out to many competing gangs. SentinelLABS traced AvNeutralizer from a single author into the toolkits of half a dozen rival operations. The kill became a commodity input the moment it had a price and a buyer. EDR killing turned into an industry the same way anything does. Someone built it well, and the rest of the market bought rather than rebuilt.

Once a tool has a price, it behaves like any other piece of software for sale. Listings imply buyers. Buyers imply reviews, resale, and pressure to ship the next version. A market does to evasion tooling what it does to everything else. It improves the product on a demand curve you do not control.

Look at the price ladder and the segmentation becomes obvious. A $300 entry point and a $3,000 ceiling on the Terminator tool is not a flat fee. It is tiered pricing, the kind a vendor sets when buyers differ in budget and need. The $4,000 to $15,000 spread on AvNeutralizer sits a tier above it. Cheap tools for low-stakes jobs, premium builds for hardened targets. Pricing tiers are a sign of a market that has matured past one seller and one product.

The naming convention carries its own signal. Sellers brand and version their killers, from Terminator to AvNeutralizer to EDRKillShifter. You do not name and version a tool you intend to use once. You name it because buyers will ask for it again, recommend it, and compare it to the competition. The naming convention is a small detail. It tells you the supply side expects repeat business.

A Market with Many Hands

The economics of the Gentlemen operation tell the rest of the story. Public reporting describes the crew handing affiliates reportedly around 90% of ransom proceeds, with centralized provisioning of the tooling. One outlet framed it as a 10% operator cut against a roughly 20% industry standard. Read that as a vendor incentive. The operators take a small margin and bet on volume, because the platform is where their advantage lives.

That split is the load-bearing number, so it deserves a careful read. A roughly 90% affiliate share is unusually generous for ransomware-as-a-service. The operator is choosing reach over margin per job. You give away most of the take when you expect a very large number of jobs. The economics describe a platform play, sized for scale rather than for any one payout.

The effect is plain once you size it. Centralized provisioning plus a reported 90% share puts kernel-level EDR evasion in the hands of low-skill affiliates. These are people who could never write it themselves. The operator carries the kernel risk. The affiliate carries the ransom note. The suite moves between them on a provisioning channel.

That division of labor is the heart of the business model. Kernel-level evasion is the hardest part of a modern intrusion to build correctly. Concentrating it in one operator and renting it out turns a rare skill into a commodity input. Every affiliate who pays gets a capability that used to gate entry to the trade. The skill floor drops to the price of admission.

Size the model and the logic gets sharper. In conventional ransomware-as-a-service, operators keep a meaningful slice, often around a fifth, to fund development and infrastructure. The Gentlemen operator keeps about a tenth. An operator gives up that much margin for one reason. The affiliate base is large enough that a thin slice still funds the shop. The revenue share is a window into scale the crew otherwise hides.

The provisioning channel reinforces the read. Threat reporting describes the suite as operator-maintained and centrally delivered, not handed over once and forgotten. That is a recurring-service relationship, the kind that throws off recurring revenue. The operator updates the tooling. The affiliate keeps coming back to the same channel. A one-time sale does not behave like that.

I want to be careful here. The rich affiliate split is a strong indicator of how fast this scaled. Calling it a proven cause would overstate the evidence. The honest read is that the economics and the surge move together. The economics make the surge cheap to sustain.

The Supply Chain Underneath the Brand

The same pattern shows up well beyond one crew. SentinelLABS traced AvNeutralizer from FIN7 into Black Basta, AvosLocker, MedusaLocker, BlackCat, Trigona, and LockBit. That is cross-crew reuse at the operator and affiliate level. It happens when the tool is a product an actor buys and carries from job to job.

A secret a single gang hoards does not spread that way. A purchased product does. The AvNeutralizer pattern is the clearest market signal in the whole dataset. One seller, many competing buyers, the same evasion capability flowing to all of them through the actors who pay for it.

The consolidation is not unique to one tool either. Public reporting documented EDRKillShifter, built and maintained by the RansomHub operation. SentinelOne®'s anthology on RansomHub describes a customized EDR killer made available to higher-level members, a tiered affiliate access model. The capability sat behind a membership tier, the way a vendor gates premium features. Higher-paying partners got the better tool.

Operator-built tooling travels under its own banner. The same EDRKillShifter code, first disclosed abusing the RentDrv2 and ThreatFireMonitor drivers, surfaced across multiple ransom-note brands. Whether the tool is rented, bought, or shared, the direction is identical. Evasion has a supplier tier, and it serves more than one storefront.

Notice what survives across these examples. RansomHub-built code outlived its association with any one affiliate. AvNeutralizer kept appearing because buyers across crews kept needing it. The constant in every case is the capability, not the crew. Defenders who chase the crew chase the part of the system that is designed to be replaceable.

This is the non-obvious part. Rival ransomware crews are not real rivals at the layer that hurts defenders. They draw from a shared supplier base for evasion, the way competing retailers buy from the same wholesaler. The brand on the ransom note changes. The thing that turns off your sensor often does not. A defender who maps these crews as separate threats misreads the board.

The market signal in cross-gang reuse is worth naming directly. The same evasion capability appears under many different ransom brands. That tells you the supplier tier consolidated faster than the affiliate tier. A defender watching ransom-note attribution sees diversity. A defender watching the kill technique sees concentration. That concentration is where a defender gains the most ground against the whole market.

What a Market Does that a Binary Does Not

A market scales. That is the entire point of building one. It is why this beats any single piece of malware on reach. A lone operator's tool dies with the operator's attention. A maintained kit with paying affiliates gets patched, re-versioned, and pushed to people who never have to understand it. The variant count, eight and growing, is the signature of a roadmap under active development. SentinelOne's latest Annual Threat Report describes the same machine multiplier across the landscape. Mature automation accelerates intrusions and compresses the window defenders have to respond.

A market also lowers the skill floor. The affiliate buying into a reported 90% split does not need kernel internals. The operator handles that. So the population capable of silencing an enterprise EDR is no longer bounded by who can write kernel exploits. It is bounded by who can pay. That is a far larger group.

A market hardens, too. When a supplier reuses tooling across crews, a takedown of one customer leaves the supplier intact. The detection a defender ships against one campaign may not survive the next build from the same shop. You are facing a software vendor's release cadence. The target moves on a schedule you do not set.

The corroboration runs across many independent shops, which matters for a claim this load-bearing. SentinelLABS documented FIN7's AvNeutralizer spreading across six named gangs. Public reporting traced EDRKillShifter under the RansomHub banner and beyond. SecurityWeek described a successful EDR killer drawing fast interest across the affiliate community as a favored asset. A CVE record (CVE-2025-68947) describes a separate ransomware family bundling a vulnerable NSecsoft driver to terminate more than 30 security processes, a capability that reads as a recruiting selling point. Different families, different reports, one direction. The kill is being marketed and sold.

Defend the Supply Chain That Feeds the Kill

So plan against the industry. The artifact is downstream of it. The instinct to hunt the specific binary, the named driver, the published hash, is what this market defeats. The published indicators, the sample filenames and the mapped techniques, are a snapshot of one release. Treating them as the whole problem is how you stay one version behind.

The durable move is to defend the behavior and the trust relationships the whole market depends on. Every variant in that kit, whatever its name this quarter, has to do the same two things. It loads a driver it does not own. It reaches kernel space to terminate a protected process. That chain is the constant. The supplier can re-skin the binary. The supplier cannot easily re-invent the move.

This is where an AI-native posture earns its place. Detection built into the kernel and reasoned over behavior watches the move itself, past whatever manifest the binary presents. It is built in, not bolted on. The Singularity™ Platform runs on Autonomous Security Intelligence (ASI) for exactly this reason. ASI pairs agentic workflows with human-level reasoning to catch the move itself, whatever manifest the binary presents.

That design watches the behavioral chain itself. Researchers have observed the kill-loop in the open. A masquerading kernel service enumerates processes in a repeating, fixed-interval termination loop. It sends PIDs through an IOCTL so the driver calls a kernel-mode termination routine, bypassing protected-process defenses. Some variants also unregister the EDR's kernel callbacks, a distinct observable that public research has tracked across more than 300 products. A design anchored to that observed chain survives when the indicators rotate and the seller ships a fresh build.

The repeating re-kill loop is itself a defensive opportunity. A tool that hammers a process list on a fixed interval leaves a rhythm in the telemetry that a single hash never reveals. The driver name will change with the next release. The killer still loads an unowned driver and reaches into kernel space to terminate protected processes. That move is the part the supplier cannot cheaply redesign. Watch it and the catalog churn underneath stops mattering as much.

Walk out of this with one frame changed. The EDR killer is a maturing software industry with operators, affiliates, suppliers, and customers. Defenders are the protagonists in that story. The work is to give the advantage to those who secure our future. Plan against the market that funds the kill. The binary that delivered it is only the receipt.

Why This is the Work SentinelOne Exists to Do

The kill is a product now, maintained and resold. The defense cannot be a static signature that ages out with the next build. The Singularity Platform watches the behavioral chain the supplier cannot cheaply redesign. It watches the unowned driver loading and the reach into kernel space to terminate a protected process. Purple AI®, the agentic security analyst at the center of the platform, turns that signal into action. Its Agentic Investigation capability runs zero-click investigations that detect and , verify, and respond on their own, compressing work that once took hours into minutes. When a kit re-skins itself overnight, the platform reasons over what the kit still has to do.

No team watches the console at three in the morning, the hour this market was built to exploit. Wayfinder, SentinelOne's managed detection and response practice, keeps that watch for you. It pairs human threat hunters with the same autonomous investigation and threat intelligence behind the scenes. That is why the company exists. The advantage belongs to the defender, and the platform is built to keep it there even as the supplier ships its next version.

Next in this series: how the kill went from a hobbyist's trick to a maintained industry, traced across a multi-year timeline.

References

  1. "The Gentlemen RaaS Uses GentleKiller to Disable EDR Defenses." The Hacker News, June 2026.

  2. "GentleKiller: Gentlemen ransomware builds an EDR killer framework." Infosecurity Magazine, 22 June 2026.

  3. "Inside GentleKiller: the EDR killer powering the Gentlemen." Security Affairs, June 2026.

  4. "Gentlemen Ransomware Gang Standardizes EDR Killing." BankInfoSecurity, June 2026.

  5. "RansomHub." SentinelOne Anthology.

  6. "Gentlemen ransomware uses multiple EDR killers to disable defenses." BleepingComputer, June 2026.

  7. "Exploring Vulnerable Windows Drivers." Cisco Talos, 19 December 2024.

  8. "LOLDrivers: Living Off The Land Drivers." Accessed June 2026.

  9. "Qilin ransomware's EDR killer." Cisco Talos, 2 April 2026.

  10. "Terminator EDR Killer (Spyboy): Detecting and Preventing a Windows BYOVD Attack." SentinelOne (SentinelLABS), updated 27 April 2025.

  11. "FIN7 Reboot: Cybercrime Gang Enhances Ops with New EDR Bypasses and Automated Attacks." Antonio Cocomazzi, SentinelLABS, 17 July 2024.

  12. "Ransomware crews flaunt their EDR-killer wares." The Register, 14 August 2025.

    1. "RansomHub ransomware uses a tool to kill EDR software." Security Affairs.

  13. "Annual Threat Report: Defending Against the Industrialization of the Modern Cyber Breach." SentinelOne.

  14. "Ransomware Groups Increasingly Adopting EDR Killer Tools." SecurityWeek.

  15. "CVE-2025-68947." National Vulnerability Database (NVD).

    1. "Reynolds ransomware uses BYOVD to disable security before encryption." Security Affairs.

  16. "Qilin EDR Killer infection chain." SOC Prime, 7 April 2026.

    1. "What Are Bring Your Own Vulnerable Driver (BYOVD) Attacks?" Picus Security.

Third Party Disclaimer:

All third-party product names, logos, and brands mentioned in this publication are the property of their respective owners and are for identification purposes only. Use of these names, logos, and brands does not imply affiliation, endorsement, sponsorship, or association with the third-party.

Related Articles

Decorative background gradient

Subscribe

Get the Latest From the SentinelOne Blog