Cybersecurity teams have faced a growing threat from a new “EDR killer” payload in recent months, often referred to as AVKiller, which has been observed disabling endpoint defenses to facilitate ransomware deployment.
See also: SonicWall: Disable SSL VPN due to ransomware

First detected in mid-2024, this tool exploits the HeartCrypt packer-as-a-service to hide its true function and go undetected by traditional static signatures. Attackers typically deliver AVKiller via a dropper that pretends to be a legitimate tool—often by injecting malicious code into signed executables like Beyond Compare.
Once executed, AVKiller decodes the protected payload in memory, looks for specific security drivers, and proceeds to terminate the relevant processes, creating a clean path for subsequent encryption . Sophos analysts identified the initial AVKiller samples targeting Sophos products, and later variants have broadened their focus to include a wide range of vendors including Bitdefender, Kaspersky, SentinelOne , and Microsoft Defender.
The tool looks for a randomly named driver file (for example, mraml.sys), loads it if it is present, and then terminates any running processes or services associated with known antivirus and EDR solutions. If the driver is missing, AVKiller creates a similarly named service and terminates with an error message, “Failed to acquire device,” ensuring that defenders encounter limited evidence of criminal activity.
See also: Interlock Ransomware uses the ClickFix technique
The impact of AVKiller has been significant. In one high-profile incident, the RansomHub team deployed the payload against a large enterprise network, successfully disabling dynamic shellcode detection and device control mechanisms before unleashing file encryption. Within minutes, critical servers were compromised and recovery efforts were hampered by the lack of active EDR protection.

Analysis of the telemetry data revealed that AVKiller executed multiple SysCall, preventing live response tools from injecting into protected processes. This level of sophistication highlights the growing trend of adversaries investing in specialized off-the-shelf tools to thwart security operations.
The infection starts with an executable dropper that is packaged by HeartCrypt, designed to evade static AV signatures. Once in memory, AVKiller uses a custom loader that decodes the embedded payload using an XOR routine. The loader enumerates the loaded drivers and looks for a randomly generated five-letter name, hardcoded within the decoded payload.
When the targeted driver is loaded, AVKiller issues direct system calls to terminate critical security processes. By bypassing user-level API (application programming interface) hooks and directly calling NtTerminateProcess, AVKiller bypasses common EDR injection points. The driver itself is digitally signed with a compromised certificate—ranging from Changsha Hengxiang Information Technology Co., Ltd. to Fuzhou Dingxin Trade Co., Ltd.—both of which have expired for years but remain unrevoked in kernel verification lists. This technique allows the driver to load without raising immediate suspicion from kernel integrity checks.
See also: Ransomware – Why July and August are “hot” for hackers too
After the successful termination of security services, the dropper activates the ransomware payload—usually associated with families such as Blacksuit, MedusaLocker and INC—completing the exploitation chain. The modular design of AVKiller allows rapid updates to target lists and packaging levels, indicating active development and sharing among competing ransomware groups. As defenders adapt, understanding and blocking the system call routines of the AVKiller loader and driver loading behavior remains critical to prevent these advanced attacks.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
