Spyboy is a threat actor observed promoting a Windows tool called "Terminator" on a Russian-speaking hacking forum. Spyboy claims the tool can terminate or bypass antivirus, EDR, and XDR products, including Windows Defender, and advertises support for Windows 7 and later. Reported pricing ranged from $300 for a single bypass to $3,000 for an all-in-one bypass. Spyboy also stated that certain EDR bypasses could not be sold individually and included a disclaimer that ransomware and lockers were not allowed. Based on the reporting, Terminator is assessed by CrowdStrike as a Bring Your Own Vulnerable Driver (BYOVD) tool rather than a novel capability. It reportedly requires administrative privileges and user acceptance of a UAC prompt. The tool was reported to drop a legitimate signed Zemana anti-malware kernel driver (zamguard64.sys or zam64.sys) into C:\Windows\System32\ under a random filename, load it, and use the resulting kernel-level privileges to kill user-mode processes belonging to AV and EDR products. The reporting notes that a 2021 proof-of-concept exploit for flaws in the Zemana driver could enable kernel-privileged command execution and could be used to terminate protected security software processes. No additional aliases or sub-groups were provided in the source content.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.