Ransomware crews are increasingly trying to blind a victim before they encrypt anything.
Analysis shows that attackers can disable endpoint detection and response tools, interrupt Windows telemetry, and target backup services to reduce the chance that defenders spot or contain the intrusion in time.
The findings focus on ten ransomware families that were least often prevented in 2026 testing data.
Play had the lowest prevention score at 13 percent, followed by BlackByte at 25 percent, while LockBit, BabLock, Magniber, FAUST, Sodinokibi or REvil, Hive, BlackKingdom, and Maori also featured in the group.
Analysts at Picus Security identified a shared pattern: ransomware operators rely on stealth and defense-impairment methods after gaining a foothold. The activity is not an initial-access technique by itself.
Instead, it helps an intruder move from a compromised machine toward widespread encryption while hiding the tools and actions that would normally raise an alarm.
The consequences can be severe. If endpoint visibility, event records, and backup operations are all disrupted, security teams lose both early warning and recovery options.
Recent reporting on ransomware actors expanding EDR killer tactics shows that the effort to neutralize defenses has become a routine stage of modern ransomware operations.
Picus Security said in a report shared with Cyber Security News (CSN) that disabling or modifying tools was one of the most common behaviors in its review.
This includes stopping security, backup, and database services, removing protection software, and clearing Windows event logs that could document what happened.
Ransomware Operators Disable EDR
BabLock illustrates the danger of that sequence. The ransomware was observed abusing a legitimate vendor uninstaller, terminating a set of antivirus, EDR, backup, and database processes, then clearing Security and System event logs.
The approach can create a short but decisive window in which encryption runs with less resistance and fewer useful records for responders.
LockBit 5.0 takes a different route by interfering with Event Tracing for Windows, a telemetry mechanism relied on by monitoring products.
Its modification makes a key event-writing function return without recording data, effectively starving dependent tools of signals.
The behavior matches coverage of LockBit 5.0 targeting major platforms, where log clearing and anti-analysis features were documented.
The report also describes payload hiding and execution techniques that make the disruption harder to catch. Sodinokibi encrypts embedded code until runtime, Magniber can run code inside another process, and Play uses legitimate-looking names and locations.
BlackByte removes traces after execution and changes timestamps, complicating an investigation that starts after files have already been locked.
Closing the Gaps Before Encryption
The practical lesson is that organizations should not judge protection by whether a security product is installed.
Teams should test whether their controls detect and block attempts to stop services, erase logs, alter Windows telemetry, inject into processes, or run through trusted system programs.
Tests should cover the full path from suspicious activity to alerting and containment. Backup systems need the same scrutiny because attackers understand their value during recovery.
Separate backup administration from ordinary domain access, keep copies isolated from the production network, and regularly test restoration using a clean environment.
Guidance in this storage and backup security checklist similarly stresses inventory, logging, access separation, and checks that ransomware protections are in place.
Defenders should also protect the records needed to investigate an incident.
Centralized, tamper-resistant logging can preserve evidence when a local Windows log is cleared, while alerts for unusual service stops, security-tool uninstall attempts, and changes to telemetry functions can reveal the attack’s preparation phase.
Least-privilege access and network segmentation can limit how far an intruder can spread once discovered.
The analysis does not point to one universal ransomware playbook, but it shows why defensive validation matters.
Security teams should rehearse response actions, review which tools can modify endpoint protection, and ensure backups are recoverable under pressure.
Earlier cases, including RansomHub EDR and antivirus bypass, underline that the fight often begins before the encryption note appears.
Indicators of compromise (IoCs):-
TypeIndicatorDescriptionFile nameBEST_uninstallTool.exeLegitimate vendor uninstaller reportedly abused by BabLock to remove endpoint protectionFile namePSexesvc.exePlay service binary name used to imitate Sysinternals PsExecFile nameReadMe.txtRansom note file name observed in Play staging activityFile nameexplorer.exeFile name referenced in BlackByte 2.0’s delayed self-deletion command
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world
The post Ransomware Operators Disable EDR, Backup Software and Windows Telemetry Before Encryption appeared first on Cyber Security News.



