Discover the latest trends and innovations in computer viruses

EDR killers are no longer a curiosity reserved for APT groups. In the first half of 2026, the French Health CERT documents their use as a nearly systematic preparatory step before deploying malicious payloads on hospital systems. ESET confirms the global trend with over a hundred variants observed in real attacks. This shift profoundly changes the infection chain and necessitates a rethink of endpoint protection.

EDR killers: neutralizing defenses as a prerequisite for infection

The classic scheme of a ransomware or Trojan attack assumed that the payload had to bypass antivirus or EDR. We are now observing a reversal of logic: the attacker disables the EDR before deploying anything. The malicious payload no longer needs to be stealthy since it operates on a machine whose detection layer has been removed.

Recommended read : Discover the latest health news and tips to take care of yourself

EDR killer variants exploit signed but vulnerable Windows drivers (a technique known as Bring Your Own Vulnerable Driver). The malicious binary loads a legitimate driver, gains kernel access, and terminates the security agent processes. The operation takes a few seconds and generates only a driver loading event in the system logs.

For SOC teams, the countermeasure involves monitoring unusual driver loads, hardening the policy for blocking vulnerable drivers via WDAC (Windows Defender Application Control), and using EDR agents equipped with kernel self-protection mechanisms. We regularly publish on Viruslab news technical analyses of these variants as soon as they appear in real conditions.

See also : Understanding the evolution from directory zone to zt-za and its alternatives in 2024

Woman discovering a ransomware alert on her laptop in a modern office

Multi-vector ransomware: three groups, three industrialized methods

Triple extortion (encryption, exfiltration, denial of service threat) has been documented for several years. What changes in 2026 is the industrialization of attack chains by structured groups that combine exploitation of zero-day vulnerabilities, compromise of the software supply chain, and coordinated deployment across multiple subsidiaries of the same company.

Three operational profiles stand out:

  • Groups targeting business software publishers to compromise updates and affect hundreds of SMEs downstream, without direct interaction with each victim.
  • Operators who purchase initial access on specialized marketplaces, then deploy ransomware in less than twenty-four hours, reducing the detection window to almost nothing.
  • Affiliates who combine targeted phishing and EDR killers to penetrate networks of companies in the healthcare or industrial sectors, where tolerance for service interruption is minimal.

The common point: each group invests in automation. Lateral movement, exfiltration, and encryption tools are packaged, versioned, and distributed like internal software products.

Offensive AI and deepfakes: phishing scales up

The use of language models by attackers is no longer limited to generating grammatically correct phishing emails. The Check Point Research AI Security 2026 report documents the transition from AI as an assistant to AI as an active operator in the attack chain.

In practice, we see the emergence of campaigns where a model dynamically generates the email content based on the target’s LinkedIn profile, adapts the language and tone, and then produces a malicious file whose name and appearance correspond to the target company’s industry. The click-through rate on these campaigns significantly exceeds that of traditional phishing campaigns.

Voice deepfakes add an additional layer. Documented cases in companies show phone calls imitating a leader’s voice to validate a transfer or authorize the installation of remote maintenance software. The combination of synthetic voice and AI-generated personalized email makes human detection very difficult.

Technical countermeasures include multi-factor authentication on financial validations, out-of-band verification (callback to a known number), and deploying solutions for detecting AI-generated content on email gateways.

Inside an open computer illustrating the spread of a computer virus through hardware components

Quantum threat and digital sovereignty: preparing for post-quantum cryptography

The quantum threat to cybersecurity is no longer a theoretical subject reserved for laboratories. Security agencies recommend that companies start now inventorying their cryptographic assets and migrating to post-quantum algorithms.

The concrete risk has a name: “harvest now, decrypt later”. State actors are currently collecting encrypted streams (health data, industrial secrets, diplomatic communications) betting on the future capability of a quantum computer to break RSA or elliptic curves. For companies handling long-lived data, the migration window is shrinking.

NIST post-quantum standards (ML-KEM, ML-DSA) have been published. The challenge for CIOs is to identify cryptographic dependencies in their business applications, VPNs, TLS certificates, and electronic signature systems. A crypto-agility audit helps map friction points before planning the transition.

SME protection and remote work: attack surfaces still underestimated

SMEs remain prime targets because they combine limited security budgets with an attack surface widened by remote work. Personal devices connected to the corporate network via VPN represent an entry vector that cloud solutions alone do not cover.

Protective measures that make a difference in this segment:

  • Segment the network to isolate remote workstations from critical resources, even on a small flat network.
  • Deploy a managed EDR solution rather than a traditional antivirus, ensuring it includes anti-tampering protection resistant to documented EDR killers.
  • Train employees specifically on AI-generated phishing campaigns, with updated simulation exercises each quarter.
  • Implement a regularly tested offline backup, the only reliable defense against ransomware that has neutralized the EDR.

Managing digital risks for small structures does not involve accumulating tools, but rather ensuring consistency between the security policy and the actual usage of employees. A poorly configured firewall protects less than a properly hardened workstation with a self-protected EDR.

Discover the latest trends and innovations in computer viruses