Windows Tools Abused to Kill AV Ahead of Ransomware Attacks
ID: 33736bdc-6450-5a68-8888-e6219f727663
STIX ID: report--33736bdc-6450-5a68-8888-e6219f727663
Feed Name: GBHackers
The report details a trend where threat actors weaponize legitimate Windows admin utilities and vulnerable drivers (e.g., Process Explorer driver via BYOVD, AuKill, PowerRun, YDArk) to gain SYSTEM/kernel privileges, terminate antivirus and EDR processes, and create a silent window to deploy ransomware (notably LockBit and MedusaLocker) and credential theft tools like Mimikatz; it warns that RaaS kits and customizable modules lower the bar for affiliates and recommends layered defenses (behavioural detection, self-protection, application control) as mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
