Skip to main content
Desktop featured image: CTI blog 3 - wide
Emerging Issue

CTI Roundup: EDR Killer, PS1Bot, Charon Ransomware

Ransomware groups adopt shared EDR-killing tool, PS1Bot spreads via malvertising, and Charon ransomware uses APT-style tactics to target critical sectors

In this week’s roundup, Tanium’s Cyber Threat Intelligence (CTI) team explores how ransomware groups are increasingly adopting a shared tool to disable endpoint detection and response (EDR) systems. We also examine a malvertising campaign distributing the modular PS1Bot malware framework and analyze the emergence of Charon ransomware—an advanced persistent threat (APT)-style attack targeting critical sectors with customized attacks.

Shared EDR-killing tool gains momentum across ransomware ecosystem

Sophos reports that ransomware groups are increasingly deploying a shared, advanced tool to disable EDR systems, evade detection, and streamline attack execution.

[Think your EDR has you covered? Learn how visibility gaps and slow response times may be leaving your endpoints exposed.]

Believed to be developed by RansomHub, the tool is considered an evolution of EDRKillShifter. It leverages signed drivers and process injection to bypass security defenses.

Threat groups including Blacksuit, Medusa, Qilin, DragonForce, Crytox, Lynx, and INC have also adopted the tool, indicating widespread use across the ransomware ecosystem.

AV killer payload found in thousands of ransomware samples

Sophos has documented this payload in thousands of samples, noting that it is frequently deployed mid-attack and often embedded in legitimate utilities to evade detection and disable antivirus defenses.

[Explore the tough decisions behind ransomware response—from whether to pay to how to prepare for the next attack—in this Tanium podcast episode.]

For example, in one instance the attackers embedded the payload into the Clipboard Compare feature of Beyond Compare—a legitimate utility from Scooter Software. Attackers injected loader code and embedded the malicious payload as a resource, accompanied by additional loader components.

Upon execution, the payload self-decoded, allowing Sophos to identify several key traits:

  • The code is heavily obfuscated and protected.
  • It looks for a drive with a five-letter random name.
  • The driver is signed via a compromised certificate.
  • It targets several security vendors.
  • The list of targets varies between samples.

The executable was confirmed as an AV killer, specifically engineered to target Sophos products. Sophos notes multiple versions exist, each varying in the security products they target.

Across these variants, the tool attempts to identify and terminate processes and services from its target list. The latest variant uses a driver signed by Fuzhou Dingxin Trade Co., Ltd.

How the EDR killer is typically deployed

Most observed attacks begin with a HeartCrypt-packed dropper, which delivers a protected EDR killer executable and loads a driver signed with a compromised certificate.

Researchers observed the executable attempting to load a paired driver, though execution is often blocked by generic static detections or dynamic protections such as SysCall or HollowProcess.

After the EDR killer was deployed, Sophos observed a ransomware alert for RansomHub—though similar sequences have preceded attacks from other ransomware families as well.

Case studies: MedusaLocker and INC Ransomware in action

To illustrate how this tool is being adapted across different ransomware families, Sophos presents two notable cases:

  1. MedusaLocker: Sophos highlights a case involving MedusaLocker ransomware, where attackers likely used an RCE zero-day in SimpleHelp for initial access. The AV killer was executed from a SimpleHelp component called JWrapper-Remote Access, targeting products from ESET, Symantec, Sophos, HitManPro, Webroot, and Kaspersky.
  2. INC: In June 2025, Sophos identified an INC ransomware attack where the actor used two packer-as-a-service tools for added protection.

These cases illustrate how the tool is being adapted across different ransomware families.

Analyst comments from Tanium’s Cyber Threat Intelligence team

The commoditization of EDR killers is a troubling development. Nefarious tools are becoming more accessible to a wider range of threat actors, and helping to increase the speed and scale of attacks.

This research from Sophos also highlights how tools are being reused and adapted by multiple ransomware groups. The increased collaboration and code sharing among cybercriminals makes activities easier to conduct, and attribution more difficult.

Malvertising campaign delivers modular PS1Bot malware framework

Cisco Talos reports that a sophisticated malvertising campaign is actively distributing PS1Bot, a modular malware framework built in PowerShell and C#. It stealthily steals credentials, captures screenshots, and evades antivirus detection—all while executing entirely in memory.

Delivered via deceptive ads and SEO poisoning, PS1Bot executes entirely in memory and evolves rapidly—posing a significant threat to both enterprise and personal cybersecurity.

Campaign overview: Malvertising and in-memory execution

Cisco Talos has been tracking an active campaign that uses malvertising to deliver a multistage malware framework.

The framework delivers additional modules—such as information stealers, keyloggers, and screen capture tools—while minimizing forensic artifacts by executing entirely in memory. Cisco Talos refers to this PowerShell-based malware as PS1Bot.

Below are key technical takeaways from the PS1Bot campaign, showing how the malware achieves stealth, persistence, and modular functionality:

  • Delivery: Victims are lured through SEO poisoning or malvertising to download a compressed archive containing a single file—FULL DOCUMENT.js. This JavaScript file functions as a downloader, initiating the next stage of the PS1Bot infection chain.
  • Stage one retrieval: Upon execution, the malware retrieves a JScript scriptlet and runs its contents to prepare for subsequent attack stages. This includes writing a PowerShell script to the ProgramData directory and executing it to establish a persistent C2 connection. The malware enters a loop, continuously contacting the C2 server for additional commands.
  • PowerShell modules: Cisco Talos observed multiple PowerShell modules delivered after the initial infection, including those for antivirus detection, screen capture, wallet grabbing, keylogging, information collection, and persistence. Most modules include embedded logging components that allow attackers to monitor both installation and runtime activity, with updates sent to the C2 server.
  • Antivirus detection: The antivirus detection module is delivered after the malware establishes a C2 connection. It gathers details about installed antivirus programs on the infected device by querying WMI and reports this information back to the C2.
  • Screen capture: The screen capture module takes screenshots using a C# assembly DLL executed via PowerShell at runtime. It creates a .BMP image file, converts it to JPEG, and transmits it to the C2 server.
  • Grabber module: The grabber module targets local browser storage, extension data, application data, and password-containing files—primarily focused on cryptocurrency wallet theft.
  • Keylogger: The keylogger module tracks keyboard and mouse activity, as well as clipboard contents, and sends the captured data to the C2.
  • Information collection: The WMIComputerCSHARP module gathers system and environment details by querying domain membership via WMI.
  • Persistence: The persistence module ensures the malware’s looping mechanism re-executes after reboot or session termination.

Together, these modules show how PS1Bot maintains stealth and persistence across infected systems.

Analyst comments from Tanium’s Cyber Threat Intelligence team

The campaign’s reliance on SEO poisoning and malvertising demonstrates how attackers are continuing to exploit user trust and search engines—emphasizing the importance of educating users about safe browsing habits and downloads, even from seemingly legitimate sources.

The Cisco Talos report also highlights another trend, which involves using native system tools like PowerShell to evade detection and persist on the device with minimal forensic traces. This makes detection exceedingly difficult.

Charon ransomware emerges with APT-style tactics targeting high-value organizations

Trend Micro has identified a new ransomware strain, Charon, which employs advanced APT-style techniques—including DLL sideloading, process injection, and anti-EDR capabilities—to execute highly targeted and disruptive attacks.

Charon ransomware: Targeted attacks and technical parallels to Earth Baxia

Charon ransomware was first observed in a targeted attack in the Middle East, affecting public and aviation sector organizations. The threat actor used DLL sideloading and other techniques reminiscent of Earth Baxia campaigns. Customized ransom notes referenced victims by name, reinforcing the targeted nature of the operation. These tactics reflect a growing trend of ransomware operators adopting APT-style methods.

The attack began with the execution of a legitimate binary, Edge.exe (renamed from cookie_exporter.exe during the attack), which was abused to sideload a malicious DLL named msedge.dll. This DLL acted as a loader, decrypting the ransomware payload and injecting it into a new svchost.exe process. By masquerading as a legitimate Windows service, the malware increases its chances of evading traditional detection mechanisms.

Trend Micro uncovered Charon’s use of multistage payload extraction. A seemingly benign file, DumpStack.log, was found to contain encrypted shellcode that ultimately delivered the ransomware payload. Forensic analysis revealed two layers of encryption protecting the final payload.

[Learn how to navigate the high-stakes world of ransomware negotiation with strategies that protect your data, reputation, and bottom line.]

Charon’s technical profile: Encryption, evasion, and targeting behaviors

Building on these findings, Trend Micro further analyzed Charon’s executable and observed its sophisticated capabilities and mature operational characteristics:

  • Initialization and parameters: Once initialized, Charon accepts parameters that control error log storage, target servers or IPs, encryption scope, and order. It also creates a mutex named OopCharonHere.
  • Pre-encryption behavior: Before encryption begins, Charon stops security-related services, terminates active processes, deletes shadow copies, and empties the recycle bin to hinder recovery. It then assesses available processor cores and spawns multiple threads for file encryption.
  • Encryption logic: During encryption, Charon avoids encrypting .exe, .dll, .Charon, and ransom note files. Encrypted files are appended with .Charon, and an infection marker—“hCharon is enter to the urworld!”—is added. The ransomware uses Curve25519 elliptic curve cryptography combined with the ChaCha20 stream cipher.
  • Post-encryption behavior: After encryption, Charon drops its ransom note across all drives, networks, and directories.

Additional behaviors include actively scanning for and encrypting accessible network shares, mapped drives, and UNC paths. Charon also includes a driver component designed to disable EDR solutions.

[Explore why relying solely on EDR could leave your organization vulnerable—and what it really takes to defend against modern cyber threats.]

Analyst comments from Tanium’s Cyber Threat Intelligence team

Ransomware operators are increasingly adopting stealthier and more sophisticated methods to improve attacks. As Trend Micro notes, this “compels enterprises to reconsider traditional approaches and strengthen their security posture with layered defenses.”

Trend Micro also includes some best practices in the report to help defend against Charon ransomware.

Do you have insight into these stories that you want to share? Head over to Tanium’s discussion forum to start a conversation.

For further reading, catch up on our recent cyber threat intelligence roundups.