Threat Management, Threat Intelligence, Vulnerability Management

Advanced NtKiller tool touts antivirus, EDR evasion on dark web

antivirus

Newly emergent defensive evasion tool NtKiller has been promoted on the dark web by threat actor AlphaGhoul as a highly advanced antivirus and endpoint detection and response bypass utility for ransomware operations and initial access brokers, reports GBHackers News.

Aside from circumventing security systems' alerts, NtKiller features Hypervisor-Protected Code Integrity, Virtualization-based Security, and Memory Integrity support, indicating potential usage of the Bring Your Own Vulnerable Driver attack technique, said KrakenLabs in a post on X, formerly Twitter. AlphaGhoul has also noted target termination at launch to guarantee the concealment of the payload.

While NtKiller on its own is available for $500, threat actors could purchase an additional NtKiller rootkit that obscures malware processes and registry keys for another $300, as well as avail the silent UAC bypass module for another $300.

Organizations' security teams have been urged to be wary of driver-based attack indicators even if AlphaGhoul's claims about NtKiller are yet to be verified.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds