Infosecurity

Ransomware Groups Have Turned EDR-Kill Into a Standard Move — Here’s What That Means

Published

on

EDR-Kill Is No Longer a Niche Trick

Shutting down endpoint detection and response (EDR) tools before deploying ransomware has moved from a specialist capability to standard operating procedure. That’s the headline finding from Halcyon‘s Q2 2026 Ransomware Evolution Report, published July 27.

The practice — often called EDR kill techniques — is now baked into the attack chains of most major ransomware groups. Researchers at Halcyon say this leaves defenders with even less time to spot and contain an intrusion. The window between initial access and encryption keeps shrinking.

One group, The Gentlemen, has made EDR and antivirus shutdown a core part of its playbook. That group has quickly become one of the most prolific ransomware threats around.

How The Gentlemen Builds Its Arsenal

Halcyon’s Ransomware Research Center previously documented how The Gentlemen’s developers reverse-engineer ransomware code from other gangs. They systematically pull apart samples from Babuk, Qilin, LockBit 5.0 and Medusa. The goal? Cherry-pick the strongest encryption routines, best code-obfuscation tricks and most effective EDR evasion methods.

It’s a modular, mix-and-match approach to building ransomware. The Gentlemen doesn’t start from scratch. It assembles a custom toolkit from proven components. That makes its attacks harder to predict and harder to block.

Attack Numbers Are Down — But Don’t Celebrate

Halcyon recorded 1,988 publicly claimed ransomware attacks in Q2 2026, carried out by 89 active groups across 101 countries. That’s a 5.7% drop quarter-on-quarter. Sounds like good news, right?

Not really. The underlying tactics got significantly more advanced. Halcyon describes a “shift towards faster, more automated and harder-to-detect operations.” Fewer attacks, but each one is more dangerous.

The top groups by claim count were:

  • Qilin — 293 claims
  • The Gentlemen — 214 claims
  • DragonForce — 143 claims
  • Akira — 119 claims
  • LockBit 5.0 — 102 claims

DragonForce and LockBit 5.0 both ramped up activity in Q2. The Gentlemen overtook Qilin for the top spot in June alone. Several new or returning groups also surfaced: KryBit, Payload, PEAR and World Leaks.

Manufacturing Takes the Biggest Hit

Manufacturing was the most targeted sector, accounting for 19.8% of all cyber extortion attacks. Construction came second, followed by business services, retail and software.

Attackers are also exploiting vulnerabilities in enterprise edge devices at scale. The most abused flaws during Q2 included Citrix NetScaler ADC and Gateway (CVE-2025-5777), SonicWall SSL VPN (CVE-2024-40766) and Fortinet‘s FortiOS (CVE-2024-55591).

Some groups — DragonForce and Akira among them — moved from initial breach to ransomware deployment in under an hour in certain attacks. That’s terrifyingly fast.

AI Is Moving From Experiment to Operations

Halcyon’s report found that AI is no longer just a toy for ransomware groups. It’s being operationalized across the attack chain. Threat actors are using malware disguised as fake AI productivity tools, AI-assisted victim negotiations, and what researchers believe is the first agentic ransomware — capable of autonomously conducting key stages of an intrusion.

One example: the LLM-developed malware EvilAI. It masquerades as AI productivity apps while secretly providing ransomware actors with initial access.

Ross Asquith, solutions engineering director for Europe at Halcyon, put it bluntly: “The democratization of EDR-kill techniques and the generalization of the use of AI in ransomware attack chains show that the ransomware ecosystem is becoming faster, more automated and far more effective at neutralizing the security tools organizations rely on.”

His advice to defenders: focus on cyber resilience. “No longer assume traditional controls will buy them the time they need to respond.”

Ransomware as a Cover for State Operations

The report also flagged a troubling trend: growing evidence of ransomware being used to support state objectives. Iran-linked actors, in particular, are increasingly disguising espionage campaigns as criminal ransomware operations. It’s a convenient cover — and one that blurs the line between cybercrime and cyberwar even further.

For defenders, the takeaway is clear. The old playbook — detect, contain, respond — is breaking. Attackers have automated EDR-kill, accelerated their timelines and started using AI. Defenders need to rethink their assumptions about how much time they actually have.

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending

Exit mobile version