AuKill is a Windows defense-evasion utility used to disable antivirus and endpoint detection and response (EDR) software before attackers deploy ransomware or backdoors. It employs a bring-your-own-vulnerable-driver (BYOVD) technique, abusing the legitimate Microsoft-signed kernel driver distributed with Sysinternals Process Explorer version 16.32 to interfere with protected security processes. AuKill has been used by ransomware affiliates in attacks involving Medusa Locker and LockBit, including incidents in early 2023, and has been sold on criminal marketplaces.
AuKill requires existing administrative privileges to operate. When not running as SYSTEM, it attempts to relaunch with elevated privileges by impersonating TrustedInstaller and duplicating its access token. It copies itself onto the compromised system, installs itself as a service, and loads the outdated Process Explorer driver. Multiple threads continuously monitor targeted processes and services, repeatedly terminating security processes and disabling services to prevent recovery. Some variants also unload security-product drivers and remove their service registrations. Observed targets include Sophos and Microsoft security components. AuKill shares substantial code and driver-interaction similarities with the open-source Backstab tool.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“The AuKill malware employs a Bring Your Own Vulnerable Driver (BYOVD) technique to disable Endpoint Detection and Response (EDR) processes.”
“The AuKill malware employs a Bring Your Own Vulnerable Driver (BYOVD) technique to disable Endpoint Detection and Response (EDR) processes.”
FIN7 also developed AuKill (also known as AvNeutralizer), a custom EDR evasion utility designed to disable endpoint security solutions, which was later reported to have been offered for sale by the group on criminal marketplaces.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
For each driver name, AuKill tries to unload it via calling NtUnloadDriver and deleting the corresponding registry key in the hive System\CurrentControlSet\Services\[DRIVER_NAME].
By leveraging a vulnerable driver, attackers can execute malicious actions in kernel mode. For example, after gaining administrative access, an attacker can install a signed but flawed driver and send it crafted commands to exploit its weaknesses. | Attackers are increasingly abusing trusted Windows drivers to turn off antivirus (AV) and endpoint detection and response (EDR) tools, using a technique known as Bring Your Own Vulnerable Driver (BYOVD).
Then it duplicates the token of TrustedInstaller.exe using the DuplicateTokenW WINAPI function, and passes the token to CreateProcessWithTokenW to elevate itself to SYSTEM once the process restarts.
Then it duplicates the token of TrustedInstaller.exe using the DuplicateTokenW WINAPI function, and passes the token to CreateProcessWithTokenW to elevate itself to SYSTEM once the process restarts.
For each service name in the list, AuKill checks if it exists, and if it does, disables it by calling ChangeServiceConfigW and passing SERVICE_DISABLED for dwStartType.
“This tool has been found in the wild as a packed payload… analysis of the associated private packer… ‘PackXOR’… The aim of packing is to hinder the work of malware analysts and antivirus/EDR software, by concealing payloads and delaying their detection.”
AuKill drops a driver named PROCEXP.SYS (from the release version 16.32 of process Explorer) into the C:\Windows\System32\drivers path. The legitimate Process Explorer driver is named PROCEXP152.sys, and normally is found in the same location.
For each driver name, AuKill tries to unload it via calling NtUnloadDriver and deleting the corresponding registry key in the hive System\CurrentControlSet\Services\[DRIVER_NAME].
FIN7 also developed AuKill (also known as AvNeutralizer), a custom EDR evasion utility designed to disable endpoint security solutions...
Then it duplicates the token of TrustedInstaller.exe using the DuplicateTokenW WINAPI function, and passes the token to CreateProcessWithTokenW to elevate itself to SYSTEM once the process restarts.
For each driver name, AuKill tries to unload it via calling NtUnloadDriver and deleting the corresponding registry key in the hive System\CurrentControlSet\Services\[DRIVER_NAME].
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malicious tool associated with BYOVD tradecraft that leverages vulnerable signed drivers to terminate or impair endpoint security processes.
Malware referenced as abusing the Process Explorer driver to kill or bypass EDR protections.
Process Explorerの正規ドライバを悪用してEDR/セキュリティ製品を停止させるEDR Killerマルウェア。ランサムウェア展開前の防御無効化に使われる。
BYOVD-associated defense-evasion tool referenced as commonly used by ransomware groups to disable security products prior to encryption.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.