HomeSecurityRansomware groups use AuKill to disable EDR software

Ransomware groups use AuKill to disable EDR software

Cybercriminals have used a malicious tool, AuKill, to compromise organizations by disabling Endpoint Detection & Response (EDR) software on their victims' systems and then introducing backdoors and ransomware in Bring Your Own Vulnerable Driver (BYOVD) attacks.

See also: Google fixes another active Chrome zero-day exploit

AuKill EDR software

In these types of attacks, criminals deploy legitimate drivers that are digitally signed with a legitimate certificate and run in the kernel security framework. This allows them to disable existing security software on victims' devices and gain complete control over the system.

This strategy has become a favorite tactic for many malicious hackers, including state-sponsored cybercrime operations and financially motivated.

See also: Microsoft Defender: Update causes chaos in Windows Hardware Stack Protection

The AuKill malware, first detected by Sophos X-Ops security researchers, drops a vulnerable Windows driver (procexp.sys) alongside the one used by Microsoft's Process Explorer v16.32. This is a very popular and legitimate utility that helps gather information about active Windows processes.

To achieve even higher levels of access, the system first determines whether it is running with SYSTEM privileges. If not, then the TrustedInstaller Windows Modules Installer service will be impersonated to advance to SYSTEM privileges.

To disable security software, AuKill starts multiple threads to continuously investigate and disable security processes and services (and ensure they stay disabled by preventing reboots ).

In 2021, AuKill has been detected being used to infect victims with the Medusa Locker and LockBit. This malware has, so far, caused at least three separate security incidents.

Ransomware groups use AuKill to disable EDR software

AuKill is similar to an open-source tool called Backstab, which uses a Process Explorer driver to disable security solutions running on compromised devices.

See also: Fortra: Publicized zero-day attacks on GoAnywhere MFT

Ransomware groups use AuKill to disable EDR software

The LockBit gang has used Backstab in at least one of attacks observed by Sophos X-Ops while examining the criminal group's latest malware version, titled LockBit 3.0 or "LockBit Black."

"We found many similarities between the open source tool Backstab and AuKill," the researchers said.

"Some of these similarities include similar, characteristic debug strings and nearly identical code flow logic for interacting with the driver."

The oldest known AuKill sample was compiled in November 2022, while the most recent was created just a few months ago and was developed by the LockBit ransomware for malicious purposes.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS