PowerTool is a Windows utility abused by threat actors during post-compromise activity to disable antivirus and endpoint detection and response (EDR) software. Its observed malicious use includes bring-your-own-vulnerable-driver (BYOVD) attacks that exploit a legitimate, signed Zemana AntiMalware kernel driver to terminate security processes at kernel level, impairing endpoint defenses before ransomware deployment. Akira ransomware operators were observed using PowerTool for this purpose in March 2024 and have also used it alongside custom scripts and KillAV to shut down antivirus services. PowerTool has additionally been deployed during Qilin-related intrusions following RDP-based initial access and lateral movement. It is an auxiliary tool used in ransomware operations, not itself a ransomware encryptor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Akira has been observed abusing the legitimate, signed Zemana anti-malware kernel driver ... via PowerTool to disable EDR at the kernel level.
CTU researchers have observed remote desktop protocol (RDP) abused for initial access and lateral movement before the post-compromise PCHunter and PowerTool tools were deployed, possibly with the intention of disabling antivirus software.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A defense-evasion tool reportedly used by Akira operators to abuse the vulnerable Zemana AntiMalware driver and terminate AV/EDR processes at kernel level.
Tool explicitly weaponized by Akira affiliates to shut down antivirus services before ransomware execution.
Tool explicitly weaponized in Akira operations to exploit an antimalware driver and disable security software. No specific driver vulnerability identifier is supplied.
Tool explicitly described as being abused in Akira attacks to disable EDR through the vulnerable Zemana kernel driver.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.