Terminator is a Windows endpoint-protection killer tool sold and advertised by the threat actor Spyboy on Russian-language criminal forums, including RAMP, as a utility to disable antivirus, EDR, and XDR products. Reporting assessed it as a Bring Your Own Vulnerable Driver (BYOVD) tool rather than a novel exploit. Terminator abuses legitimate but vulnerable Zemana-signed drivers, specifically zam64.sys and zamguard64.sys, associated with Zemana Anti-Logger and Zemana Anti-Malware. These drivers contain insufficient validation around IOCTL access, allowing an attacker to add their own process to an allow list via IOCTL 0x80002010 and then request actions such as terminating protected processes via IOCTL 0x80002048.
Observed and reported behavior includes dropping a legitimate signed Zemana kernel driver to disk, including into C:\Windows\System32\ under a random filename, loading it as a service or driver to gain kernel-level privileges, and then using that access to kill user-mode security processes. Sophos tracked multiple Terminator variants, including an open-source Terminator project, SharpTerminator written in C#, and Ternimator written in Nim. Attackers were also observed modifying or repacking Terminator-derived code to evade detection; in one case, an EXE named ter.exe unpacked into a slightly modified Terminator variant, decrypted an embedded resource with AES-256 using a hardcoded key, and contained a PDB path referencing Terminator-master.
Use of Terminator requires administrative privileges, and reporting notes that installation of the vulnerable driver may require a UAC bypass or social engineering to obtain user approval. Sophos observed real-world incidents in late 2023 involving Terminator variants, including attacks likely exploiting vulnerable Citrix applications for initial access, followed by attempts to disable Sophos protections using WMIC and then Terminator. In another healthcare-sector intrusion, attackers attempted to run Ternimator before installing XMRig, and Sophos blocked the driver load. In a separate December 2023 incident, an attacker attempted to load the Zemana Anti-Logger driver masquerading as updatedrv.sys from %sysdir%\drivers\updatedrv.sys and <d>\programdata\usoshared\updatedrv.sys, then switched to AuKill after the Zemana-based attempt failed.
Spyboy advertised Terminator as capable of disabling 24 security products and priced it from $300 to $3,000. The tool has been associated with ransomware intrusion activity and broader defense-evasion operations. High-confidence indicators and artifacts mentioned in reporting include the vulnerable driver names zam64.sys and zamguard64.sys, random driver filenames, ter.exe, updatedrv.sys, the PDB string Terminator-master, and the relevant Zemana IOCTL codes 0x80002010 and 0x80002048.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A threat actor known as Spyboy is promoting a tool called "Terminator" ... that can allegedly terminate any antivirus, XDR, and EDR platform. However, CrowdStrike says that it's just a fancy Bring Your Own Vulnerable Driver (BYOVD) attack.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
BYOVD (Bring Your Own Vulnerable Driver) is a class of attack in which threat actors drop known vulnerable drivers on a compromised machine and then exploit the bug(s) to gain kernel-level privileges. | To abuse the driver in this way, however, a threat actor would need administrative privileges and a User Account Control (UAC) bypass... So while leveraging vulnerable legitimate drivers could certainly allow a threat actor to terminate AV and EDR processes...
In some cases, threat actors also ported the open-source projects discussed earlier to different languages or obfuscated them through packers to circumvent detection.
"...drops the legitimate, signed Zemana anti-malware kernel driver... into the C:\Windows\System32\ folder with a random name between 4 and 10 characters."
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A BYOVD tool used to disable security products by abusing vulnerable Zemana drivers (zam64.sys or zamguard64.sys) to terminate protected processes.
An EDR killer referenced as another example of malware using similar proof-of-concept-derived techniques to hinder or disable endpoint defenses.
Referenced as another EDR-killer family exhibiting similar development patterns (e.g., leveraging/porting public proof-of-concept driver exploits).
A Windows post-exploitation tool that disables/terminates AV/EDR/XDR user-mode processes by dropping and loading a legitimate but vulnerable, signed Zemana anti-malware kernel driver to gain kernel-level capabilities (BYOVD). Requires admin privileges and UAC approval to run.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.