EDR killers explained: Beyond the drivers
2026-03-20T08:51:40Z•7b558d1861f7d5b61fff0be6f26a5ddf4867aa4e952636f56b67afed892f3faa
APTAndroid malwareCVE-2025-50165DynoWiperEDR evasionEDR killersESETGenerative AILongNosedGoblinMDRPromptSpySandwormSednitWindows Imaging Componentcredential stuffingdeepfakesdriver exploitationfacial recognition bypassmobile securityphishingransomwarespywarethreat researchvulnerable driversweLiveSecurity
What happened
Collection of ESET WeLiveSecurity research and guidance published between Dec 2025 and Mar 2026. Key items include an in-depth look at the “EDR killer” ecosystem and how attackers abuse vulnerable drivers, the discovery of PromptSpy (first known Android malware to incorporate generative AI in its execution flow), technical analysis of DynoWiper and attribution to Sandworm, a revisit of CVE-2025-50165 (Windows Imaging Component), plus reporting on APT activity (Sednit, LongNosedGoblin), facial-recognition bypass techniques, and multiple operational guidance pieces for businesses and consumers (
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- eset_welivesecurity
- Record identifier
- 7b558d1861f7d5b61fff0be6f26a5ddf4867aa4e952636f56b67afed892f3faa
- Enrichment time
- 2026-03-20T08:51:40Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.