Sophos X-Ops reported that the AuKill malware uses a bring-your-own-vulnerable-driver (BYOVD) technique to disable endpoint detection and response tools before follow-on payloads such as ransomware or backdoors are deployed. The tool abuses an outdated, Microsoft-signed Process Explorer driver, PROCEXP.SYS, and was linked to at least three intrusions involving ransomware operators including Medusa Locker and LockBit. Researchers identified six variants developed between late 2022 and early 2023, indicating active refinement of the malware.
AuKill requires administrative privileges, installs itself as a Windows service, drops the vulnerable driver into the system drivers directory, and repeatedly kills processes and disables services tied to security products; some versions also unload defensive drivers. Sophos said the malware shares strong code and behavioral similarities with the open-source Backstab project, suggesting the author reused existing offensive techniques to build the tool. The findings highlight continued criminal use of signed but vulnerable drivers to evade defenses and weaken security controls ahead of broader compromise.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
A GitHub repository named 'Killers' was published, presenting tooling for exploitation of process-killer drivers. This is a new public technical disclosure related to the driver-abuse technique used to terminate security processes.
Sophos X-Ops publicly reported its analysis of AuKill, describing it as a bring-your-own-vulnerable-driver tool that reuses code and techniques similar to the open-source Backstab project. Sophos said it detects the malware as ATK/BackStab-D and highlighted malicious driver abuse as a growing trend.
In early 2023, Sophos linked AuKill to at least three ransomware incidents, including attacks involving Medusa Locker and LockBit. In these intrusions, the tool was used to disable endpoint detection and response software before ransomware or backdoor deployment.
From November 2022 through February 2023, Sophos observed six AuKill variants, indicating ongoing refinement of the tool's capabilities for terminating processes, disabling services, and in some cases unloading security drivers.
Sophos identified the earliest known AuKill malware variant in November 2022, marking the start of observed development of the defense-evasion tool. The malware abused an outdated Microsoft-signed Process Explorer driver to disable security products.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcenews.sophos.com
Open sourcesophos.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.