logo

Technical Analysis: Killer Ultra Malware Targeting EDR…

ID: ce21dfb9-83bc-54e1-b3b1-4ac1409e2efd

STIX ID: report--ce21dfb9-83bc-54e1-b3b1-4ac1409e2efd

Feed Name: TrustedSec blog

Threat Score
78/100

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

ARC Labs analyzed 'Killer Ultra', a malware component used in Qilin ransomware attacks that leverages a vulnerable Zemana driver (CVE-2024-1853) to gain kernel-level process termination capabilities, enabling it to disable popular EDR/AV products (Symantec, Microsoft Defender, SentinelOne), clear Windows Event Logs, and persist via scheduled tasks; the report includes a sample hash and detection guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.