Single Vulnerable Driver Disables 300+ EDRs, Undermining Endpoint Diversity

A single vulnerable signed driver loaded via DLL side-loading can disable over 300 endpoint detection and response (EDR) kernel drivers across multiple vendors. Qilin and Warlock ransomware operators actively exploit this by using a malicious msimg32.dll to run an in-memory EDR killer that terminates these drivers, delaying ransomware encryption by six days. This attack breaks the assumption that using multiple EDR vendors provides resilience because it targets the shared kernel trust boundary. Even after patching or removing vulnerable drivers, defenders must assume possible persistence and focus on detecting in-memory EDR-killer behaviors and network exfiltration. This represents a critical shift in how kernel-mode drivers can be weaponized to neutralize broad endpoint defenses simultaneously.

Part of the PlainSec briefing for 2026-04-07

Sources