KillAV is a Windows defense-impairment tool used to disable antivirus and endpoint detection and response software on compromised systems. It deploys vulnerable kernel drivers and abuses their functionality through bring-your-own-vulnerable-driver (BYOVD) techniques to terminate security processes at kernel level. Its use includes abuse of Zemana AntiMalware drivers. KillAV is also used to stop security-related services and uninstall antimalware solutions, reducing detection and interference with subsequent attacker activity.
KillAV has been deployed in ransomware intrusions associated with TargetCompany, Medusa, Akira, REvil, Conti, and Hive. It is frequently paired with vulnerable drivers in Medusa attacks to disable endpoint defenses before ransomware deployment. Its use is not limited to financially motivated operations: the China-linked espionage actor Jewelbug has also deployed KillAV to disable security software, including during an intrusion into a Taiwanese software company. KillAV functions as an auxiliary defense-evasion component rather than the ransomware encryptor or espionage backdoor used in these operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
They also use custom scripts and tools like PowerTool and KillAV to shut down antivirus services.
We also observed TargetCompany dropping KILLAV to terminate security-related processes and services.
In almost all Medusa attacks, KillAV and associated vulnerable drivers are used... to disable security software... Dropping AVKiller and a driver...
2 distinct techniques documented for this family, organized by ATT&CK tactic.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A defense-evasion tool reportedly used by Akira operators to abuse the vulnerable Zemana AntiMalware driver and terminate AV/EDR processes at kernel level.
Tool used to disable/kill security software as part of the defensive evasion stage prior to ransomware deployment.
Tool used to deploy (typically) vulnerable drivers to terminate security processes as part of defense evasion in ransomware intrusions.
Tool referenced as used to terminate/disable antivirus processes as part of Medusa-related intrusion activity (BYOVD/defense evasion).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.