MS4Killer is a Rust-based endpoint detection and response (EDR) killing tool used by the Embargo ransomware-as-a-service operation. It was developed by modifying concepts from the publicly available s4killer proof of concept and is deployed by Embargo’s MDeployer loader before ransomware execution. MS4Killer uses a bring-your-own-vulnerable-driver (BYOVD) technique to obtain kernel-level capability and terminate selected security-product processes through a minifilter communication mechanism. It performs process and service enumeration and targets endpoint security products, including Microsoft Defender and products from SentinelOne, Cylance, ESET, Bitdefender, Kaspersky, and Webroot. MS4Killer builds are custom compiled for victim environments so that their process-targeting logic corresponds to installed security tooling, reducing the value of hash-based detection. It is used against Windows systems as a defense-evasion stage preceding Embargo ransomware deployment and encryption.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
MS4Killer uses the vulnerable probmon.sys driver to terminate victim-specific security-product processes through a minifilter communication port.
At the time, Embargo relied on two EDR killers: a custom Safe Mode script, leveraging the technique already described earlier, and MS4Killer, a tool inspired by the publicly available s4killer PoC.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
EDR killers register scripts and services to run early at boot to interfere with EDR loading.
Commercial EDR killers especially use obfuscation and encryption (e.g., CardSpaceKiller).
Some EDR killers embed the drivers directly into their user-mode components, often encrypted.
Embargo has encrypted both MDeployer and MS4 Killer payloads with RC4.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Rust-based BYOVD EDR killer used with Embargo. It decrypts and loads a vulnerable driver (probmon.sys), creates kernel services, and continuously terminates victim-specific security products such as SentinelOne, Cylance, ESET, Defender, Bitdefender, Kaspersky, and Webroot.
Rust-based defensive-security-product killer used with Embargo. It uses a bring-your-own-vulnerable-driver technique, creates and loads a kernel-driver service, then continuously identifies and terminates selected EDR and antivirus processes. Builds are custom compiled for individual victims.
EDR killer used by Embargo; based on the s4killer PoC but modified with parallelism, altered code flow, and encrypted strings and embedded driver.
Toolkit used alongside Embargo to disable or terminate security software and processes, enumerate processes, and deploy a vulnerable driver as part of BYOVD activity to facilitate ransomware execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.