SpyBoy, also styled Spyboy, is a threat actor known for developing and selling Terminator, a Windows security-disabling tool marketed on Russian-speaking hacking forums beginning in May 2023. The actor advertised prices ranging from $300 for a product-specific bypass to $3,000 for an all-in-one package. Terminator uses a bring-your-own-vulnerable-driver (BYOVD) technique involving a legitimate, signed Zemana anti-malware kernel driver. It exploits vulnerable driver functionality to terminate antivirus and endpoint detection and response processes with kernel-level privileges. The Zemana arbitrary process termination vulnerability incorporated into the tool is identified as CVE-2024-1853. Running Terminator requires existing administrative privileges and approval of a User Account Control prompt. Its principal capability is defense evasion through disabling endpoint security software; advertised claims of broad product coverage are not independently established. SpyBoy's sale of Terminator does not establish affiliation with Qilin or other ransomware operators.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
5 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as background to the Zemana vulnerability: SpyBoy incorporated it into Terminator and marketed the security-disabling tool on Russian hacking forums for $300–$3,000. The content does not establish a connection between SpyBoy and Qilin or Killer Ultra.
Promotes and sells an EDR/AV-killer tool (“Terminator”) on a Russian-speaking forum. The tool is described as a BYOVD-style capability that drops and loads a legitimate signed Zemana anti-malware kernel driver to gain kernel privileges and terminate user-mode security processes (AV/EDR/XDR), requiring admin privileges and UAC acceptance on the target.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.