Spyboy is a threat actor persona observed advertising a Windows defense-evasion tool called Terminator on a Russian-speaking cybercrime forum. The tool is marketed as capable of terminating or bypassing multiple antivirus, EDR, and XDR products on Windows systems. Available reporting indicates the capability is not a novel exploit chain but an implementation of the bring-your-own-vulnerable-driver (BYOVD) technique, in which a legitimate signed but vulnerable kernel driver is deployed and abused to gain kernel-level access for disabling user-mode security processes. Terminator reportedly requires administrative privileges on the target host and user approval of a UAC prompt, after which it loads a vulnerable Zemana anti-malware driver to obtain kernel-level privileges and kill protected security tooling processes. This places Spyboy’s advertised capability squarely in the defense-evasion and post-compromise tooling ecosystem commonly used to neutralize endpoint protections before follow-on activity. Although the seller included language disallowing ransomware use, such disclaimers do not materially constrain downstream criminal use, and BYOVD-based security-tool termination is widely associated with intrusion enablement, including ransomware deployment. High-confidence public information currently supports characterization of Spyboy primarily as a cybercriminal seller or operator associated with defense-evasion tooling rather than as a clearly attributed nation-state actor. No corroborated sub-groups, broader cluster attribution, or additional aliases are established from the available facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.