216.73.216.6

ThrottleStop driver abused to terminate AV processes

· Published 06/08/2025 12:25 · Modified 06/08/2025 17:04

Export JSON

Essential information

Published
06/08/2025 12:25
Modified
06/08/2025 17:04
Tags
2025-08-06 CVE-2025-7771 av killer byovd driver abuse kernel exploitation medusalocker ransomware throttlestop
Related entities
4 techniques (mitre), 1 malware, 5 others

Description

A recent incident response case in Brazil revealed a new antivirus (AV) killer software circulating since October 2024. This malware abuses the .sys driver to terminate numerous antivirus processes, employing a technique known as (Bring Your Own Vulnerable Driver). The attack began with a valid RDP credential, followed by lateral movement using pass-the-hash techniques. The , consisting of ThrottleBlood.sys and All.exe, exploits a vulnerability () in the legitimate driver to disable system defenses. The malware targets multiple antivirus processes from various vendors, using kernel function hijacking to terminate them. Victims have been identified primarily in Russia, Belarus, Kazakhstan, Ukraine, and Brazil.

External references