Пожалуйста, обратите внимание, что пользователь заблокирован
‘AuKill’ EDR killer malware abuses Process Explorer driver
Driver-based attacks against security products are on the rise
news.sophos.com
Кек.
For example, the driver can receive the IO control code IOCTL_CLOSE_HANDLE from user-mode applications, which commands the driver to close a protected process handle, resulting in terminating a process.
The tool was used during at least three ransomware incidents since the beginning of 2023 to sabotage the target’s protection and deploy the ransomware: In January and February, attackers deployed Medusa Locker ransomware after using the tool; in February, an attacker used AuKill just prior to deploying Lockbit ransomware.