Threat Advisory

AuKill EDR killer malware Abuses Process Explorer Driver

Threat: Malware
Criticality: High
[subscribe_to_unlock_form]

Summary:

Researchers has investigated a number of events over the past few months where attackers tried to disable EDR clients using the new defence evasion tool AuKill. Before installing a backdoor or ransomware on the target machine, the AuKill tool disables EDR processes by abusing an outdated driver used by Microsoft's Process Explorer version 16.32.[/subscribe_to_unlock_form]

Summary:

Researchers has investigated a number of events over the past few months where attackers tried to disable EDR clients using the new defence evasion tool AuKill. Before installing a backdoor or ransomware on the target machine, the AuKill tool disables EDR processes by abusing an outdated driver used by Microsoft's Process Explorer version 16.32.[emaillocker id="1283"]

The AuKill malware contains six different variations, which Researchers have gathered through analysis and threat hunting. Researchers have discovered numerous parallels between AuKill, and the open-source utility Backstab. Some of these similarities include typical debug strings that are comparable and almost identical code flow logic to communicate with the driver. Researchers believe the author of AuKill copied various snippets of code from Backstab and built their malware around it. Such attacks use genuine drivers that are signed with a working certificate and capable of executing with kernel privileges to disable security features and take control of the machine. This method is common among a variety of threat actors, from state-sponsored hacking outfits to ransomware gangs with financial motives.

It first checks to see if it is already operating with SYSTEM privileges; if not, it pretends to be the TrustedInstaller Windows Modules Installer service and requests SYSTEM privileges. AuKill launches a number of threads to continuously scan for and stop security processes and services, as well as to ensure that they stay disabled by preventing them from restarting.

Several AuKill versions have so far been seen in the wild, some of which have been used in at least three distinct incidents that have resulted in the infection of Medusa Locker and LockBit ransomware since the year's beginning. Since the beginning of 2023, the tool has been used in at least three ransomware instances to undermine the target's defences and spread the malware. 

Threat Profile:

References:

The following reports contain further technical details:

https://www.bleepingcomputer.com/news/security/ransomware-gangs-abuse-process-explorer-driver-to-kill-security-software/

[/emaillocker]
crossmenu