News Room
16
Share
RansomHub Escalates Global Healthcare Offensive via EDRKillShifter and ESXi Exploitation
criticalThreat Intelligence

RansomHub Escalates Global Healthcare Offensive via EDRKillShifter and ESXi Exploitation

RansomHub has emerged as the most prolific RaaS threat of July 2026, utilizing the sophisticated EDRKillShifter tool to disable security protections before exfiltrating terabytes of patient data.

19 July 2026Last updated 20 August 20265 min readCrowdStrike
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here

Executive Takeaway — TL;DR

Category:
Threat Intelligence
Severity:
Critical
Actor Type:
Ransomware Group
Geography:
Global
Confidence:
High Confidence
Source:
CrowdStrike
Read Time:
5 min

Executive Summary

In the last 48 hours, Encrygma Intelligence has tracked a significant surge in activity from the RansomHub ransomware-as-a-service (RaaS) group, specifically targeting major healthcare providers across North America and Europe. This latest campaign demonstrates a marked increase in technical sophistication, characterized by the deployment of the 'EDRKillShifter' tool and the exploitation of critical vulnerabilities in virtualization infrastructure. RansomHub has effectively filled the power vacuum left by the 2024 disruption of LockBit and ALPHV, leveraging a highly competitive 90% affiliate payout model to attract high-tier cybercriminal talent. Current assessments suggest that at least four mid-sized hospital networks have been compromised since July 17, with attackers threatening to leak a combined 3.5TB of sensitive PHI (Protected Health Information).

Threat Analysis

RansomHub represents a sophisticated evolution in the RaaS landscape. Unlike legacy groups that relied on broad, automated phishing, RansomHub affiliates are increasingly utilizing targeted 'smash-and-grab' tactics combined with prolonged persistence for double extortion. The group's strategy focuses on 'Pressure-Point Targeting'—selecting sectors like healthcare where operational downtime directly impacts human safety, thereby increasing the likelihood of rapid ransom payments. The group operates under a strict 'CIS-exempt' policy, typical of Russian-aligned syndicates, and has recently integrated tools previously associated with the Scattered Spider (Octo Tempest) threat actor group, suggesting a deep level of collaboration between initial access brokers and payload developers.

Technical Details

The current campaign utilizes a multi-stage execution chain. Initial access is frequently obtained through sophisticated vishing (voice phishing) or the exploitation of unpatched vulnerabilities in edge-facing VPN appliances. Once inside the perimeter, the attackers deploy 'EDRKillShifter,' a specialized payload that employs 'Bring Your Own Vulnerable Driver' (BYOVD) tactics to terminate Endpoint Detection and Response (EDR) agents. By loading a legitimate but vulnerable driver (such as a legacy version of a motherboard utility), the malware gains kernel-level permissions to kill security processes that would otherwise block the ransomware. Lateral movement is achieved via Cobalt Strike beacons and the abuse of legitimate administrative tools like AnyDesk and WinSCP. The final payload is a Go-based encryptor specifically optimized for VMware ESXi environments, allowing the group to cripple entire virtualized server farms simultaneously. Data exfiltration is streamlined using a customized Rclone configuration that pushes data to S3-compatible buckets before the encryption routine begins.

Attribution Assessment

Encrygma assesses with high confidence that RansomHub is a Russian-speaking threat actor group. Code analysis reveals significant overlaps with the Knight (Cyclops) ransomware source code, supporting the theory that RansomHub is either a rebrand or an evolution of that lineage. Furthermore, the recruitment of former 'Scattered Spider' affiliates indicates a globalized workforce, though the core command-and-control infrastructure remains anchored in Eastern European hosting providers. The group's negotiation style is professional and disciplined, often utilizing a dedicated .onion portal that assigns a unique 'Client ID' to each victim, a hallmark of organized cybercrime syndicates.

Implications

The targeting of healthcare during a period of increased digital transformation poses an existential risk to provider operational continuity. The use of EDR-disabling tools marks a shift where traditional signature-based and behavioral defenses are rendered ineffective if kernel-level protection is compromised. Furthermore, the massive exfiltration of PHI creates long-term regulatory and legal liabilities for victims, as RansomHub has shown no hesitation in selling 'unpaid' data to secondary brokers on the dark web. The financial impact of these attacks is estimated to exceed $150 million in the last 48 hours alone when factoring in remediation costs and potential ransoms.

Recommendations

Encrygma recommends that organizations immediately implement a strict driver blocklist (e.g., via Microsoft's recommended driver block rules) to mitigate BYOVD attacks. Ensure that all ESXi hosts are updated to the latest patch level and that SSH access is disabled unless strictly necessary. Organizations should move toward FIDO2-compliant multi-factor authentication to neutralize vishing-based credential theft. Finally, backup repositories must be physically or logically isolated from the primary network to ensure recovery is possible even if domain admin privileges are compromised.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo