Figure 3 shows the ransom note that RansomHub affiliates leave on their victims’ machines. On June 21st, 2024, RansomHub operators changed the affiliate rules in reaction to an alleged breach by security researchers. RansomHub’s EDR killer, named EDRKillShifter by Sophos , is a custom tool developed and maintained by the operator. EDRKillShifter is offered to RansomHub affiliates through the web panel, same as the encryptor; it too is protected by a 64-character password. Roughly a month after EDRKillShifter’s announcement, on June 3rd, 2024, RansomHub operators posted yet another update, stating that they improved EDRKillShifter.