Trojan.Win64.KILLLAV.I is a defense-evasion utility observed in Warlock ransomware intrusion chains. Trend Micro reported that attackers deployed this binary, including under the filename vmtools.exe, to enumerate running processes and terminate selected processes listed in a log file, primarily targeting security software. In the observed cases, the targeted processes were associated with Trend Micro security products. The malware was used after initial access in campaigns exploiting vulnerable on-premises Microsoft SharePoint servers, including attacks linked in reporting to Storm-2603 and broader Warlock activity. Within those intrusions, attackers used it alongside other post-compromise actions such as privilege escalation through Group Policy changes, activation of the built-in guest account with elevated privileges, command-and-control via Cloudflare Tunnel, credential dumping with Mimikatz, lateral movement over SMB, and eventual ransomware deployment. High-confidence identifiers from the content include the detection name Trojan.Win64.KILLLAV.I and the observed filename vmtools.exe.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Trojan.Win64.KILLLAV.I is a custom malware used for defense evasion in ransomware attacks. It enumerates and terminates security software processes, drops and installs a malicious driver, and repeatedly kills targeted processes to facilitate ransomware deployment.
Process-termination tool used for defense evasion by enumerating and killing security-related processes (notably targeting Trend Micro security product processes in the observed activity).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.