top of page
perceptive_background_267k.jpg

Ransomware gangs turn to Shanya EXE packer to hide EDR killers

Published:

9 december 2025 om 00:00:05

Alert date:

9 december 2025 om 00:00:38

Source:

bleepingcomputer.com

Click to open the original link from this advisory

Multiple ransomware groups are utilizing Shanya, a packer-as-a-service (PaaS) platform, to obfuscate and hide EDR (endpoint detection and response) killing tools. This development represents a concerning trend where ransomware operators are leveraging commercial services to evade security defenses. The use of packers allows attackers to disguise malicious payloads and bypass detection mechanisms that would normally identify and block EDR termination attempts. This technique significantly increases the likelihood of successful ransomware deployment by neutralizing endpoint security solutions before encryption begins.

Technical details

Mitigation steps:

Affected products:

EDR Solutions

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page