HeartCrypt-Packed EDR Killer (AVKiller): The New Weapon in Ransomware Campaigns
Date: August 8, 2025
Here's the uncomfortable part of the HeartCrypt story: by the time it runs, your EDR is already losing. In August 2025, Sophos X-Ops documented ransomware crews using a tool called HeartCrypt, a packer-as-a-service (PaaS), to switch off Endpoint Detection and Response (EDR) and antivirus (AV) products before they drop their ransomware payloads.
That's a real shift in how these crews operate. It also shows how far cybercrime-as-a-service has come, with groups openly sharing tooling instead of building their own.
Where HeartCrypt Came From
RansomHub built HeartCrypt, growing it directly out of the EDRKillShifter tool from earlier campaigns. That lineage matters, because the capability didn't stay in-house. At least eight ransomware groups now run HeartCrypt in their attacks: RansomHub, Blacksuit, MedusaLocker, Qilin, DragonForce, Crytox, Lynx, and INC.
This is cybercrime-as-a-service working exactly as designed. One crew writes the tool, the rest rent or buy it. The proliferation is semi-coordinated, with customized builds, shared obfuscation tricks, and tool reselling all in the mix. It mirrors the way a real software vendor ships product, which is precisely what makes it dangerous.
How HeartCrypt Actually Runs
At its core, HeartCrypt injects malicious code into legitimate, signed executables. From a detection-engineering seat, that's the whole problem in one sentence: the thing your tools trust is the thing carrying the payload. Here's the sequence.
1. Delivery
Ransomware groups push HeartCrypt through EDR killer droppers or trojanized utilities. One example Sophos flagged: Beyond Compare's Clipboard Compare tool, compromised to carry a malicious payload.
2. Payload Execution
Once the payload fires, it decodes itself and launches an obfuscated binary. That binary then hunts for a five-letter driver (for example, mraml.sys or noedt.sys) signed with either compromised or expired certificates. Using BYOVD (Bring Your Own Vulnerable Driver), HeartCrypt loads a kernel driver that impersonates trusted security software such as CrowdStrike Falcon Sensor.
3. EDR/AV Termination
With the driver sitting in the kernel, it starts terminating EDR and AV processes. Endpoint defenses go down, and the box is wide open for the ransomware stage.
4. Obfuscation and Evasion
HeartCrypt wraps all of this in multi-stage packing and resource encryption, which makes detection by traditional static or behavioral analysis tools almost impossible.
Which Products Get Disabled
HeartCrypt can take down a long list of leading endpoint protection tools, including:
- Sophos
- Microsoft Defender
- Kaspersky
- Trend Micro
- SentinelOne
- McAfee
- Bitdefender
- Cylance
- F-Secure
- Symantec
- Webroot
- HitmanPro
...and plenty of others.
Why This Hurts Defenders
One of the nastier traits here is HeartCrypt's ability to disrupt dynamic shellcode detection and bypass device control mechanisms. RansomHub showed how that lets them deploy ransomware fast and quietly, with little chance of detection or response.
Sophos X-Ops researchers also noted that every HeartCrypt attack used unique, group-specific builds. That tells you these weren't smash-and-grab jobs with an off-the-shelf tool. They were planned. In the EDR-bypass investigations I've worked, that detail is the tell that you're up against an organized operation, not a script kiddie.
The Strategic Problem
Faster Attack Chains
Because HeartCrypt is commoditized and widely adopted, the time from initial access to encryption keeps shrinking. The underground ecosystem behind it mimics legitimate software development, and that maturity makes detection and mitigation harder.
Driver Signing You Can No Longer Trust
Signing drivers with expired or stolen legitimate certificates (the BYOVD approach) undermines trust in the driver-signing model itself. When the signature on a kernel driver no longer proves it's safe, one of your core validation methods stops meaning much.
The Limits of AI-Only Defense
Custom obfuscation, BYOVD, and deep encryption together show that AI-based security tools alone may not catch these tailored threats. Layered, adaptive controls matter more than ever, and so does at least one detection path that doesn't depend on the endpoint agent staying alive.
What To Do About It
To defend against HeartCrypt-packed EDR killers and similar threats, work through this list:
- Patch and monitor remote access tools, such as SimpleHelp, to prevent unauthorized access.
- Enforce strict driver-signing policies, and configure alerts for revoked, expired, or untrusted driver certificates.
- Set up alerts for mass termination of security processes and services, which surfaces suspicious activity early.
- Deploy application allowlisting, especially for binaries in user or temp directories, to block unauthorized executables.
- Train your security teams to recognize anomalous driver behavior and signs of EDR tampering.
- Run red-team simulations regularly to test your resilience against EDR-killing techniques and BYOVD attacks.
- Use Indicators of Compromise (IOCs) from security vendors to proactively block known threats.
- Adopt AI-enhanced detection and Zero Trust principles across your stack to cut risk.
The MINE2 Angle
HeartCrypt is exactly the kind of threat that beats signature- and behavior-based EDR, because it's built to turn that EDR off first. This is where cyber deception earns its keep, and it's a point I've made in why deception survives EDR killers: your detection shouldn't all live on the same endpoint the attacker just disabled.
How MINE2 helps:
- Deception-based detection that doesn't rely on signatures or behavioral patterns
- Honeypot systems that flag attacker presence even after EDR is terminated
- Credential honeytraps that fire the moment attackers attempt lateral movement
- Network deception that stays live even when endpoint agents are down
See how MINE2 catches EDR killers with our deception platform.
Key Takeaways
HeartCrypt-packed AVKiller is part of a new wave of ransomware toolkits that hand cybercriminals a reliable way to disable endpoint defenses. The BYOVD exploits and deep obfuscation let attackers slip past strong endpoint protection, often until it's already too late.
The cooperation between ransomware groups and the tool-as-a-service model make defense harder than it used to be. Staying ahead takes proactive, layered defenses: continuous patching, driver-signing enforcement, team training, and adaptive controls that don't all collapse when the endpoint agent dies.
A layered approach, with regular patching, policy enforcement, strong detection, and Zero Trust, is what builds real resilience for 2025 and beyond.
References & Further Reading
- Sophos X-Ops Report: "Shared Secret: EDR Killer in the Kill Chain"
- SC Media / BleepingComputer: Coverage on Tool Adoption by Ransomware Groups
- Security Boulevard / Sophos: Analysis of Tool-Sharing and HeartCrypt Usage
- Cybersecurity News: Detailed AVKiller Behavior and Impact
- Palo Alto Networks Unit42 Threat Blog: Ransomware Evolution
Arjun
Lead Detection Engineer, Mine2
Arjun builds detection logic at Mine2, focusing on the blind spots EDR and SIEM leave behind and how honeytokens close them.
Recent Articles
Need Security Help?
Protect your organization with MINE2's cyber deception platform.

