Technical Analysis: Killer Ultra Malware Targeting…
ID: 77847c33-747c-51b3-92a8-d7e8cd2089d4
STIX ID: report--77847c33-747c-51b3-92a8-d7e8cd2089d4
Feed Name: Binary Defense Blog
Threat Score
ARC Labs analyzed "Killer Ultra," a malware component used in Qilin ransomware operations that disables endpoint security by unpacking and installing a vulnerable Zemana AntiLogger driver (CVE-2024-1853) to terminate AV/EDR processes, clear Windows Event Logs, establish persistence via scheduled tasks, and contains inactive code for downloading/executing post-exploitation tools; ARC Labs provides detection queries and a sample hash.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
