logo

Windows Tools Abused to Kill AV Ahead of Ransomware Attacks

ID: 33736bdc-6450-5a68-8888-e6219f727663

STIX ID: report--33736bdc-6450-5a68-8888-e6219f727663

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-03-31

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

The report details a trend where threat actors weaponize legitimate Windows admin utilities and vulnerable drivers (e.g., Process Explorer driver via BYOVD, AuKill, PowerRun, YDArk) to gain SYSTEM/kernel privileges, terminate antivirus and EDR processes, and create a silent window to deploy ransomware (notably LockBit and MedusaLocker) and credential theft tools like Mimikatz; it warns that RaaS kits and customizable modules lower the bar for affiliates and recommends layered defenses (behavioural detection, self-protection, application control) as mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.