RansomHub ransomware abuses Kaspersky TDSSKiller to disable EDR software

Share:

The RansomHub ransomware gang has been using TDSSKiller, a legitimate tool from Kaspersky, to attempt disabling endpoint detection and response (EDR) services on target systems.

After taking down the defenses, RansomHub attempts to deploy the LaZagne credential-harvesting tool to extract logins from various application databases that could help move laterally on the network.

TDSSKiller abused in ransomware attacks

Kaspersky created TDSSKiller as a tool that can scan the system for the presence of rootkits and bootkits, two types of malware that are particularly difficult to detect and can evade standard security tools.

EDR agents are more advanced solutions that operate, at least partially, at the kernel level, as they need to monitor and control low-level system activities such as file access, process creation, and network connections, all providing real-time protection against threats like ransomware.

Cybersecurity company Malwarebytes reports that they recently observed RansomHub abusing TDSSKiller to interact with kernel-level services using a command line script or batch file that attempts to disable Malwarebytes Anti-Malware Service (MBAMService) running on the machine.

Commands supported by TDSSKiller
Command parameters supported by TDSSKiller
Source: Malwarebytes

The tool was employed following the reconnaissance and privilege escalation phase, and executed from a temporary directory (‘C:\Users\<User>\AppData\Local\Temp\’) using a dynamically generated filename (‘{89BCFDFB-BBAF-4631-9E8C-P98AB539AC}.exe’).

Being a legitimate tool signed with a valid certificate, TDSSKiller does not risk RansomHub’s attack getting flagged or stopped by security solutions.

ADVERTISING

Next, RansomHub used the LaZagne tool in an attempt to extract credentials stored in databases using LaZagne. In the attack that Malwarebytes investigated, the tool generated 60 file writes that were likely logs of the stolen credentials.

The action to delete a file could be the result of the attacker trying to cover their activity on the system.

Defending against TDSSKiller

Detecting LaZagne is straightforward as most security tools flag it as malicious. However, its activity can become invisible if TDSSKiller is used to deactivate the defenses.

TDSSKiller is in a gray area, as some security tools, including Malwarebytes’ ThreatDown, label it as ‘RiskWare’, which could also be a red flag to users.

The security firm suggests activating the tamper protection feature on the EDR solution, to make sure that attackers can’t disable them with tools like TDSSKiller.

Additionally, monitoring for the ‘-dcsvc’ flag, the parameter that disables or deletes services, and for the execution of TDSSKiller itself can help detect and block the malicious activity.

Bill Toulas

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
12:58 pm, Jun 22, 2025
weather icon 25°C
L: 24° | H: 27°
scattered clouds
Humidity: 48 %
Pressure: 1013 mb
Wind: 15 mph WSW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 40%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:43 am
Sunset: 9:21 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
24° | 27°°C 0 mm 0% 17 mph 64 % 1013 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
15° | 23°°C 0.2 mm 20% 15 mph 81 % 1016 mb 0 mm/h
Tue Jun 24 10:00 pm
weather icon
14° | 26°°C 0 mm 0% 16 mph 77 % 1015 mb 0 mm/h
Wed Jun 25 10:00 pm
weather icon
16° | 27°°C 0 mm 0% 9 mph 86 % 1013 mb 0 mm/h
Thu Jun 26 10:00 pm
weather icon
17° | 24°°C 1 mm 100% 15 mph 95 % 1018 mb 0 mm/h
Today 1:00 pm
weather icon
24° | 25°°C 0 mm 0% 15 mph 49 % 1013 mb 0 mm/h
Today 4:00 pm
weather icon
21° | 24°°C 0 mm 0% 17 mph 47 % 1013 mb 0 mm/h
Today 7:00 pm
weather icon
21° | 22°°C 0 mm 0% 13 mph 54 % 1012 mb 0 mm/h
Today 10:00 pm
weather icon
16° | 16°°C 0 mm 0% 10 mph 64 % 1012 mb 0 mm/h
Tomorrow 1:00 am
weather icon
16° | 16°°C 0 mm 0% 13 mph 76 % 1011 mb 0 mm/h
Tomorrow 4:00 am
weather icon
16° | 16°°C 0.2 mm 20% 13 mph 81 % 1011 mb 0 mm/h
Tomorrow 7:00 am
weather icon
15° | 15°°C 0.2 mm 20% 13 mph 60 % 1013 mb 0 mm/h
Tomorrow 10:00 am
weather icon
17° | 17°°C 0 mm 0% 13 mph 46 % 1014 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€89,130.15
-1.14%
Ethereum(ETH)
€1,973.05
-6.88%
Tether(USDT)
€0.87
0.02%
XRP(XRP)
€1.75
-5.37%
Solana(SOL)
€115.37
-6.59%
USDC(USDC)
€0.87
0.00%
Dogecoin(DOGE)
€0.134923
-4.92%
Shiba Inu(SHIB)
€0.000010
-5.18%
Pepe(PEPE)
€0.000008
-9.01%
Peanut the Squirrel(PNUT)
€0.218233
13.10%
Scroll to Top