AuKill
Aliases: SophosKill
- First seen
- 2023-02-01 00:00:00
- Malware type
- ransomware, backdoor
- Profile updated
- 2026-07-07 14:46:22
Targeted industries: technology-and-telecommunications financial-services healthcare-and-pharmaceutical
Context
According to Sophos, the AuKill tool abuses an outdated version of the driver used by version 16.32 of the Microsoft utility, Process Explorer, to disable EDR processes before deploying either a backdoor or ransomware on the target system.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Aukill_Auto (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Aukill (report)
- news.sophos.com — Aukill Edr Killer Malware Abuses Process Explorer Driver (report)