HavocKiller is a Windows bring-your-own-vulnerable-driver security-disabling tool used in ransomware intrusions to terminate or suppress endpoint protection products at kernel level. It is also referred to as HwAudKiller and is known for abusing a vulnerable Huawei audio driver to gain the privileged access needed to interfere with defensive software. Public reporting placed its disclosure in March 2026, while incident telemetry showed operational use dating back to at least January 2026.
The tool has been observed as part of the broader anti-EDR ecosystem used by The Gentlemen ransomware-as-a-service operation. In that context, HavocKiller appears to be an externally sourced or third-party component rather than an in-house development, alongside other security-killing tools such as HexKiller and ThrottleBlood. The Gentlemen integrated these tools into a standardized evasion suite, applying common disguising and packing practices to make binaries resemble legitimate security software and complicate analysis and attribution.
HavocKiller’s primary role is defense evasion during the pre-encryption phase of ransomware attacks. By abusing a vulnerable signed driver, it enables privileged process termination from kernel space, helping attackers disable EDR and antivirus products before data theft or ransomware deployment proceeds. High-confidence reporting supports its use in Windows ransomware operations and its classification as a BYOVD-based EDR killer rather than a general-purpose payload.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
HavocKiller, which abuses a Huawei audio driver.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
ESET’s assessment is that all three were acquired externally by the operators and then standardized with the same defense evasion layer applied to GentleKiller: binary protection via Enigma or Themida, filenames mimicking security vendors, fabricated version information, copied digital signatures, and matching icons.
Execution T1059.003 Command and Scripting Interpreter: Windows Command Shell GentleKiller and related tools are console-based executables that run visibly and emit debug strings during execution.
T1027 Obfuscated Files or Information Some executables are protected with packers (e.g., Enigma, Themida) and custom control-flow obfuscation.
To bypass inspection, the binaries carry fake version details, copied but invalid digital signatures and the icons of the vendors they mimic, often wrapped in commercial packers.
Stealth T1036 Masquerading Gentlemen’s EDR killers are protected by impersonating legitimate vendors through filenames, version information, icons, and copied digital certificates.
T1036.001 Masquerading: Invalid Code Signature The protection applied to Gentlemen’s EDR killers adds an invalid code signature as part of the impersonation strategy.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A BYOVD EDR killer using a Huawei audio driver, integrated into The Gentlemen's evasion toolkit.
A named EDR-killer tool in the Gentlemen portfolio that disables protections by abusing a Huawei audio driver.
A third-party EDR killer adapted into Gentlemen’s portfolio and wrapped with Gentlemen’s evasion layer. It abuses a vulnerable driver impersonating Huawei’s audio stack to disable endpoint defenses during ransomware activity.
An EDR killer integrated into Gentlemen’s suite that abuses a Huawei Audio driver to evade or disable endpoint defenses.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.