TrueSightKiller is a Windows BYOVD-based EDR/AV killer tool used to disable endpoint security by abusing a vulnerable signed driver. The content consistently describes it as leveraging the vulnerable truesight.sys driver, and in Silver Fox activity the driver was also referenced as 189atohci.sys / TrueSight anti-rootkit driver material. Its core behavior is termination of antivirus and EDR processes, including via DeviceIoControl using IOCTL 0x22e044 in reported Silver Fox chains. It is described as an open-source or underground tool and as one of the more popular BYOVD utilities alongside GhostDriver, AuKill, Poortry, Gmer, and Warp AVKiller.
The malware/tool is associated in the content with multiple threat contexts. It was used by the China-linked Silver Fox / Void Arachne actor in campaigns targeting healthcare organizations and public sector entities, including intrusions involving trojanized medical software such as Philips DICOM viewer-themed lures. In those chains, TrueSightKiller was used in a second-stage defense-evasion step after retrieval of encrypted configuration and image-spoofed payloads from Alibaba OSS infrastructure, after which additional malware such as ValleyRAT/Winos 4.0, keyloggers, and cryptocurrency miners were deployed. The content also cites an August 2024 DragonForce intrusion against a UK organization in which TruesightKiller was used for defense evasion following likely RDP-based initial access.
Behaviorally, TrueSightKiller loads a vulnerable driver to obtain kernel-level capability and kill security processes, fitting the broader BYOVD pattern of abusing trusted but flawed drivers on Windows. The content notes that such tools are used to bypass or degrade AV/EDR protections and are common in ransomware and intrusion operations. High-confidence identifiers directly mentioned include the filenames TRUESIGHTKILLER.EXE, truesight.sys, and 189atohci.sys; classification as W32.Riskware.Killav - EDR/AV killer; and the IOCTL value 0x22e044 used to terminate antivirus processes in one reported chain.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The second stage focuses on disabling endpoint security through a Bring Your Own Vulnerable Driver (BYOVD) attack, loading the TrueSightKiller driver (189atohci.sys) to terminate antivirus processes using DeviceIoControl with IOCTL 0x22e044.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
By leveraging a vulnerable driver, attackers can execute malicious actions in kernel mode. For example, after gaining administrative access, an attacker can install a signed but flawed driver and send it crafted commands to exploit its weaknesses. | Attackers are increasingly abusing trusted Windows drivers to turn off antivirus (AV) and endpoint detection and response (EDR) tools, using a technique known as Bring Your Own Vulnerable Driver (BYOVD).
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A tool used in Bring Your Own Vulnerable Driver (BYOVD) attacks to abuse trusted vulnerable Windows drivers and terminate antivirus and EDR/security processes.
An anti-security/anti-rootkit driver component referenced as part of the SilverFox-style chain; in this sample, ranchserv.jpg is described as signed TrueSight anti-rootkit driver material with file materialization confirmed.
BYOVD-associated defense-evasion tool referenced as commonly used by ransomware groups to disable security products prior to encryption.
A BYOVD tool that abuses the vulnerable truesight.sys driver.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.