Backstab is an open-source Windows security-disabling tool first published in June 2021 and subsequently abused in ransomware intrusions. It uses a legitimate, Microsoft-signed Sysinternals Process Explorer driver to bypass endpoint protections and terminate endpoint detection and response (EDR)-protected processes. This bring-your-own-vulnerable-driver (BYOVD) technique enables attackers to impair antivirus and EDR defenses before deploying ransomware.
Backstab has been used by Black Basta operators and LockBit affiliates to reduce security-tool interference with file encryption. A LockBit-affiliated actor used it to disable EDR processes in November 2022. The separate security-disabling tool AuKill shares closely similar driver-interaction logic and debug strings with Backstab. Backstab is a defense-evasion utility rather than a ransomware encryptor; the encryption and data-extortion activities of its users are not capabilities of the tool itself.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Actors then disable antivirus products (in some instances using a tool called Backstab) in order to mitigate any interferences and begin encrypting files.
Backstab ... Terminates endpoint detection and response (EDR)-protected processes.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
The binary will load a vulnerable PROCEXP driver (version 16.32) which is enable user to perform arbitrary file termination by sending a specific IO control code. One of the most important of part is that the vulnerable driver is a Microsoft signed driver which most of the anti-malware products will just ignore it if they didn’t revoke the signed cert in their database.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named tool listed as part of Black Basta affiliates' toolkit; the content does not describe functionality beyond being used/abused in operations.
An open-source tool that abuses the Process Explorer driver to disable or terminate EDR/security processes. Sophos states AuKill appears to reuse core techniques and code snippets introduced by Backstab.
An open-source tool that abuses the Process Explorer driver to disable or terminate EDR/security processes. The article states AuKill appears built around the core technique introduced by Backstab.
Custom/third-party tool used to impair defenses by disabling EDR tooling prior to encryption/exfiltration stages.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.