AuKill

Aliases: SophosKill

First seen
2023-02-01 00:00:00
Malware type
ransomware, backdoor
Profile updated
2026-07-07 14:46:22

Targeted industries: technology-and-telecommunications financial-services healthcare-and-pharmaceutical

Context

According to Sophos, the AuKill tool abuses an outdated version of the driver used by version 16.32 of the Microsoft utility, Process Explorer, to disable EDR processes before deploying either a backdoor or ransomware on the target system.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Aukill_Auto (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Aukill (report)
  • news.sophos.com — Aukill Edr Killer Malware Abuses Process Explorer Driver (report)

External references