logo

Technical Analysis: Killer Ultra Malware Targeting…

ID: 77847c33-747c-51b3-92a8-d7e8cd2089d4

STIX ID: report--77847c33-747c-51b3-92a8-d7e8cd2089d4

Feed Name: Binary Defense Blog

Threat Score
78/100

Date Published: 2025-08-12

Date Updated: 2026-04-27

...
...

ARC Labs analyzed "Killer Ultra," a malware component used in Qilin ransomware operations that disables endpoint security by unpacking and installing a vulnerable Zemana AntiLogger driver (CVE-2024-1853) to terminate AV/EDR processes, clear Windows Event Logs, establish persistence via scheduled tasks, and contains inactive code for downloading/executing post-exploitation tools; ARC Labs provides detection queries and a sample hash.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.