A packer-as-a-service platform called Shanya is being used by several ransomware gangs to assist in the deployment of payloads that deactivate endpoint detection and response solutions on victim systems.
Cybercriminals can use specialized tools from packer providers to package their payloads in a way that obfuscates harmful code and avoids detection by the majority of security products and antivirus engines.
According to telemetry data from Sophos Security, malware samples utilizing the Shanya packer operation have been observed in Tunisia, the United Arab Emirates, Costa Rica, Nigeria, and Pakistan since it first appeared in late 2024.
Medusa, Qilin, Crytox, and Akira are among the ransomware groups that have been found to have used it; the latter is the most frequent user of the packers service.
Threat actors send Shanya their harmful payloads, and the service uses encryption read more about Ransomware gangs turn to Shanya EXE packer to hide EDR killers.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
