Source: Cyber Security News
Author: Guru Baran
URL: https://cybersecuritynews.com/realblindingedr-tool/
RealBlindingEDR Tool That Permanently Turns Off AV/EDR Using Kernel Callbacks
ONE SENTENCE SUMMARY:
RealBlindingEDR is an open-source tool used to disable antivirus and endpoint detection software by manipulating kernel callbacks.
MAIN POINTS:
- RealBlindingEDR blinds, disables, or terminates AV/EDR by clearing kernel callbacks.
- Released on GitHub in 2023, it uses signed drivers for memory operations.
- It exploits vulnerable drivers to gain kernel-level access without detection.
- The tool targets six major kernel callback types to bypass security.
- Ransomware groups like Crypto24 have used it in recent attacks.
- Compatible with Windows 7 to 11 and various servers, ensuring wide applicability.
- Demonstrated against 360 Security Guard, Tencent, Kaspersky, Windows Defender, and more.
- Blinding mode prevents monitoring of behaviors like malware drops.
- Requires a signed driver and admin rights for deployment.
- Organizations are advised to monitor vulnerable driver loads and kernel anomalies.
TAKEAWAYS:
- RealBlindingEDR poses significant risks despite being designed for research purposes.
- Microsoft and vendors recommend driver signature enforcement to mitigate threats.
- Security teams must review endpoint logs for unusual sys file access.
- Advanced EDR with behavioral analytics can help detect anomalies.
- Awareness and monitoring are crucial to counteract this evolving threat.