Terminator is a Windows defense-evasion utility marketed in criminal forums and used in intrusions to disable antivirus, EDR, and XDR products through a bring-your-own-vulnerable-driver (BYOVD) technique. It is associated with the threat actor Spyboy, who advertised it in 2023 as a service capable of terminating multiple security products, and it has also been observed in ransomware operations including activity linked to Akira. Terminator is not a novel kernel exploit framework so much as an operationalized wrapper around abuse of legitimate signed but vulnerable Zemana drivers to gain kernel-level capability and kill protected user-mode security processes.
The tool requires administrative privileges and, in reported tradecraft, installation of the vulnerable driver may depend on user approval of a UAC prompt or other means of obtaining elevated execution. Terminator drops and loads a signed Zemana driver, then abuses insufficient validation in the driver’s IOCTL handling to add an attacker-controlled process to an allow list and request privileged actions, including termination of targeted security processes. Multiple variants and derivatives have been tracked, including open-source Terminator builds as well as reimplementations such as SharpTerminator and Ternimator, indicating that the codebase has been adapted, repackaged, and obfuscated by different actors.
Observed use shows Terminator functioning primarily as a post-compromise defense-evasion tool rather than an initial access mechanism. In ransomware intrusions, attackers have attempted to use it after gaining privileged access in order to neutralize endpoint protections before deploying follow-on payloads. Akira operators were observed attempting to use the open-source version shortly after its public release, although at least some EDR products and Microsoft Defender detected the tool without losing protection. Other incidents show attackers modifying Terminator-derived binaries, pairing them with separately dropped vulnerable drivers, or switching to alternative BYOVD tools such as AuKill when Zemana-driver-based attempts failed.
Terminator exemplifies the broader commoditization of BYOVD tradecraft. Its appeal lies in using legitimate signed drivers with known vulnerabilities to obtain kernel-level influence without developing a custom driver. This makes it useful to ransomware affiliates and other criminal operators seeking reliable security-tool termination on Windows endpoints. The malware’s practical role is to facilitate later-stage actions by weakening host defenses, enabling execution of ransomware, cryptominers, or other payloads.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A threat actor known as Spyboy is promoting a tool called "Terminator" ... that can allegedly terminate any antivirus, XDR, and EDR platform. However, CrowdStrike says that it's just a fancy Bring Your Own Vulnerable Driver (BYOVD) attack.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
In some cases, threat actors also ported the open-source projects discussed earlier to different languages or obfuscated them through packers to circumvent detection.
"...drops the legitimate, signed Zemana anti-malware kernel driver... into the C:\Windows\System32\ folder with a random name between 4 and 10 characters."
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A BYOVD tool used to disable security products by abusing vulnerable Zemana drivers (zam64.sys or zamguard64.sys) to terminate protected processes.
An EDR killer referenced as another example of malware using similar proof-of-concept-derived techniques to hinder or disable endpoint defenses.
Referenced as another EDR-killer family exhibiting similar development patterns (e.g., leveraging/porting public proof-of-concept driver exploits).
A Windows post-exploitation tool that disables/terminates AV/EDR/XDR user-mode processes by dropping and loading a legitimate but vulnerable, signed Zemana anti-malware kernel driver to gain kernel-level capabilities (BYOVD). Requires admin privileges and UAC approval to run.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.