Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
MalwareRansomware

HRSword

HRSword is a legitimate commercial security tool associated with the Huorong Network Security Suite that has been repeatedly repurposed by ransomware operators to disable endpoint protection and EDR products on compromised Windows systems. Reporting cited here describes it as a kernel-driver-based component/tool from Huorong Network Technology / Beijing Huorong Network Technology Co., Ltd., and in one case notes it is designed to monitor various system components and provide broad system visibility. Across multiple incident-response and threat-intelligence reports, attackers installed or executed HRSword as part of defense-evasion activity, often alongside other security-disabling utilities such as kill.exe, PCHunter, GMER, YDark, WKTools, DumpGuard, and StpProcessMonitorByovd, and frequently in conjunction with vulnerable or signed kernel drivers.

Observed malicious use cases center on ransomware intrusions. Cisco Talos reported Crytox affiliates using HRSword to disable a target’s EDR after exploiting a public-facing application lacking MFA. Huntress observed HRSword in an August 2025 KawaLocker/KAWA4096 intrusion that began with access via a compromised RDP account; the actor used tasklist/find to identify security tooling, after which security-related services crashed, and installed/removed Huorong-signed drivers via sc.exe. Symantec reported Trigona affiliates installing HRSword as a kernel driver service and repurposing it to disable security software before credential theft, remote access, and custom data exfiltration. Talos also noted HRSword in broader ransomware engagements in 2025, and Qilin intrusions were reported using tools such as dark-kill and HRSword to terminate security software.

The malware/tool has therefore been associated in the provided content with Crytox, KawaLocker (KAWA4096), Trigona, and Qilin ransomware activity. The sectors explicitly mentioned in related reporting include manufacturing and construction in some ransomware campaigns, and Trigona activity targeting high-value documents such as invoices and PDFs on network drives. High-confidence indicators from the Huntress case include HRSword executable s.exe SHA256 ecca86e9b79d5a391a433d8d782bf54ada5a9ee04038dbaf211e0f087b5dad52, hrwfpdrv.sys SHA256 01a3dabb4684908082cb2ac710d5d42afae2d30f282f023d54d7e945ad3272f5, and sysdiag.sys SHA256 11b262c936ffa8eb83457efd3261578376d49d6e789c7c026f1fa0b91929e135. In that same incident, the drivers hrwfpdr/sysdiag were reported as signed with certificates issued by Beijing Huorong Network Technology Co., Ltd. Overall, HRSword is best characterized here as a legitimate Huorong security utility that has been co-opted as an EDR-killer/defense-evasion tool in ransomware attack chains.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

MITRE ATT&CK

Techniques & procedures

8 distinct techniques documented for this family, organized by ATT&CK tactic.

Persistence

1 technique
T1543.003Windows ServiceEvidence2

The kernel drivers installed as part of the threat actor’s tooling, sysdiag.sys and hrwfpdr.sys, were installed and later removed using a batch file that employed the Service Control Manager, sc.exe. Service Control Manager commands such as sc start <driver>, sc stop <driver>, and sc delete <driver> were observed in EDR telemetry.

Privilege Escalation

2 techniques
T1068Exploitation for Privilege EscalationEvidence2

Many of these tools exploit vulnerable kernel drivers to terminate endpoint protection processes, bypassing standard user-mode defenses by operating at the deepest level of the operating system.

T1543.003Windows ServiceEvidence2

The kernel drivers installed as part of the threat actor’s tooling, sysdiag.sys and hrwfpdr.sys, were installed and later removed using a batch file that employed the Service Control Manager, sc.exe. Service Control Manager commands such as sc start <driver>, sc stop <driver>, and sc delete <driver> were observed in EDR telemetry.

Stealth

1 technique
T1211Exploitation for Defense EvasionEvidence2

Before deploying the custom uploader, attackers disable security tools using multiple utilities, including HRSword, PCHunter, and GMER, often abusing vulnerable kernel drivers to kill protections.

Discovery

2 techniques
T1057Process DiscoveryEvidence1

The threat actor was then observed running tasklist.exe piped through a find command to locate specific tooling of interest, and then deploying tools to disable those security tools.

T1082System Information DiscoveryEvidence1

The threat actor deployed kill.exe and HRSword, which is designed to monitor various system components and can give them visibility across the system.

Impact

1 technique
T1489Service StopEvidence1

ESET said it also identified script-based tools that make use of built-in administrative commands like taskkill, net stop, or sc delete to interfere with the regular functioning of security product processes and services.

Other

2 techniques
T1562Impair DefensesEvidence5

Several means were employed by the threat actor to identify and “remediate” security tooling on the endpoint... deploying tools to disable those security tools. Shortly after, the Windows services associated with those installed security tools were observed crashing.

T1562.001Disable or Modify ToolsEvidence4

Once a Quick Assist session is established, the adversary loads tooling to collect information about the target system and establish persistence... disable endpoint protections... Of note, we also observed the affiliates using HRSword to disable the target’s EDR solution.

INDICATORS OF COMPROMISE

IOCs tracked for this family

3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Hashes
3 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

TypeValueLatest sighting
hash.sha256●●●●●●●●●●●●View more in app10 months ago
hash.sha256●●●●●●●●●●●●View more in app10 months ago
hash.sha256●●●●●●●●●●●●View more in app10 months ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching3

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping8

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.