Terminator is a Windows bring-your-own-vulnerable-driver (BYOVD) loader and endpoint-security disabling tool advertised by the threat actor Spyboy on the Russian-language criminal forum RAMP beginning in May 2023. It loads legitimately signed but vulnerable Zemana Anti-Malware or Anti-Logger kernel drivers and abuses their process-termination functionality to kill antivirus and endpoint detection and response processes. Insufficient authorization checks in the drivers allow an attacker-controlled process to become authorized to issue privileged requests, enabling security-process termination from kernel context. Driver installation requires administrative privileges; execution can also require User Account Control approval.
Terminator has been used by Akira and Agenda/Qilin ransomware operators to impair defenses in compromised environments. Its ecosystem includes an open-source implementation, the C# variant SharpTerminator, and the Nim variant Ternimator. Modified implementations have used packing and encrypted embedded resources to hinder detection. Terminator-related activity has also been observed in a healthcare intrusion involving attempted XMRig deployment. Its effectiveness depends on endpoint protections: observed attempts have been blocked by behavioral detection, driver-load prevention, and tamper protection. Advertised claims of bypassing numerous security products do not establish universal effectiveness.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Killer Ultra is packed with a vulnerable version of Zemana AntiLogger leveraging CVE-2024-1853 for Arbitrary Process Termination.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In May 2023, a threat actor with the pseudonym “SpyBoy” incorporated this vulnerability into a tool named “Terminator,” marketed as an "EDR killer" tool.
“Spyboy’s Terminator tool [is] used to bypass AVs and EDRs.”
8 distinct techniques documented for this family, organized by ATT&CK tactic.
In some cases, threat actors also ported the open-source projects discussed earlier to different languages or obfuscated them through packers to circumvent detection.
"...drops the legitimate, signed Zemana anti-malware kernel driver... into the C:\Windows\System32\ folder with a random name between 4 and 10 characters."
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Endpoint-defense termination toolkit mentioned only as a comparison. The reference describes it as operating against lists containing more than 300 security processes; it does not establish its use in the Silver Fox campaign.
A defense-evasion/EDR-killing tool reportedly used by Akira operators.
A purpose-built loader referenced as an example of tooling that makes vulnerable-driver abuse accessible to less sophisticated threat actors.
A BYOVD tool used to disable security products by abusing vulnerable Zemana drivers (zam64.sys or zamguard64.sys) to terminate protected processes.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.