AvNeutralizer, also known as AuKill, is a specialized Windows anti-security tool associated with the FIN7 cybercrime group and later used by multiple ransomware operators. It is designed to impair endpoint protection, particularly EDR and antivirus products, by interfering with protected security processes and services from user mode and kernel mode. The tool has been marketed in criminal underground forums, customized for buyers to target specific security products, and observed in intrusions that culminated in ransomware deployment.
AvNeutralizer’s core purpose is defense evasion. Earlier variants abused vulnerable drivers to terminate or tamper with protected security processes from the kernel. Later versions introduced a technique using built-in Windows driver functionality together with a Process Explorer driver to destabilize or crash some protected security processes, expanding the tool’s ability to bypass endpoint defenses without relying solely on traditional vulnerable third-party drivers. Reporting indicates the malware employs numerous user-mode and kernel-mode methods to disable or degrade security tooling.
The malware has been linked to FIN7’s tooling ecosystem and was initially observed in use by Black Basta before broader adoption by other ransomware groups. Subsequent intrusions associated with AvNeutralizer involved operators deploying ransomware including AvosLocker, MedusaLocker, BlackCat, Trigona, and LockBit. Its commercialization reflects a service-oriented model in which FIN7 or affiliated operators supplied tailored anti-EDR capability to other criminal actors.
AvNeutralizer targets Windows environments and is relevant primarily in post-compromise phases, where attackers use it to suppress detection before privilege escalation, lateral movement, and ransomware execution. Victim sectors associated with FIN7 activity more broadly include hospitality, energy, finance, high-tech, retail, and manufacturing.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Употребата на вграден Windows драјвер како kernel offensive primitive ... претходно била демонстрирана во контекст на FIN7’s AvNeutralizer, кој го злоупотребил Windows драјверот ProcLaunchMon.sys...
The tool, known as AvNeutralizer, is used by criminal hackers to bypass threat detection systems on victims' devices.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
The packer employs anti-analysis techniques... The final PE payload is unpacked with two iterations of XOR decryption, separated by a step of LZNT1 decompression.
Researchers have previously discovered that the tool was used exclusively for six months by another hacker group, Black Basta.
Most of these techniques are already documented, such as removing the PPL protection through the vulnerable RTCore64.sys driver...
Ова му овозможува на BTR.sys физички да ги отстрани безбедносните бинарни датотеки, како WdFilter.sys и MsMpEng.exe , пред тие да можат да се заштитат од бришење. Во демонстрација во живо ... истражувачите покажале како BTR_CLI го брише целиот Defender stack ... иако била активна Tamper Protection .
16 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Офанзивна алатка поврзана со FIN7, спомната како претходен пример за злоупотреба на Windows драјвери за манипулација со endpoint безбедносен софтвер.
An offensive tool associated with FIN7 that weaponized Windows drivers to tamper with endpoint security software.
A custom tool designed to disable or evade endpoint security products, sold/shared to support ransomware operations.
A specialized tool developed by FIN7 to disable or tamper with endpoint security products. It uses multiple user-mode and kernel-mode techniques, including abuse of vulnerable or permissive drivers and a newer technique leveraging ProcLaunchMon.sys to induce denial-of-service conditions in protected security processes.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.