logo

From Armillaria loader to EDR killer

ID: 5554b28e-645c-5e9f-b29a-dcb1bc4a804f

STIX ID: report--5554b28e-645c-5e9f-b29a-dcb1bc4a804f

Feed Name: ThreatLocker Blog

Threat Score
80/100

Date Published: 2025-12-12

Date Updated: 2026-05-01

...
...

ThreatLocker Threat Intelligence analyzed an Armillaria loader (version.dll) and a second-stage EDR-killer (owned2.dll) linked to Akira ransomware affiliates; the loader drops an embedded payload executed via rundll32.exe, and the second stage leverages a vulnerable ThrottleStop driver (rwdrv.sys) to load an unsigned malicious driver (hlpdrv.sys) that can terminate endpoint security processes, modify DACLs/security descriptors, and render files inaccessible; the samples include locale-based execution checks to avoid CIS countries, and the report provides SHA-256 hashes and mitigation guidance for customers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.