New ‘BlackSanta’ EDR killer spotted targeting HR departments
What happened
Decrypted PowerShell scriptSource: Aryaka The malware performs system fingerprinting and sends the information to the command-and-control (C2) server, and then performs extensive environment checks to stop execution if sandboxes, virtual machines, or debugging tools are detected. It also modifies Windows Defender settings to weaken security at the host, performs disk-write tests, and then downloads additional payloads from the C2, which are executed via process hollowing, inside legitimate processes. This matters for IT, Telecom & Cyber because fresh price movement and input-cost detail should reset bid assumptions, breach response slas, and negotiation guardrails with 1.0, 2.0.1, 1 as the clearest commercial anchors; expect renewal uplift asks
Buyer takeaway
For IT, Telecom & Cyber, this is a staffing-shape signal: remote operating models can shift work offsite and change which suppliers, systems, and service levels matter most
Cost / money
The cost angle is directional, not quantified: moving work offsite can cut travel, rotation, and accommodation exposure, but only if the remote setup stays reliable
Supplier / commercial
Expect scope to move toward software support, communications uptime, cyber obligations, and clearer downtime liability instead of only offshore headcount or hardware supply
Safety / operations
Fewer people offshore can reduce exposure and emergency-response load, but the operating model becomes more dependent on connectivity resilience, remote support readiness, and cyber hygiene
What to watch
Watch bandwidth resilience, latency tolerance, cyber obligations, and who carries downtime cost if the remote link drops
Key facts
- Decrypted PowerShell scriptSource: Aryaka The malware performs system fingerprinting and send
- It also modifies Windows Defender settings to weaken security at the host, performs disk-writ
- The core function of BlackSanta is to terminate security processes, which it does by: enumera
- Looking at the IP addresses, the researchers uncovered that the malware also downloaded Bring
