KillSwitch

First seen
2023-02-15 00:00:00
Malware type
ransomware
Family
Malware family
Profile updated
2026-07-07 16:03:14

Targeted industries: financial-services healthcare-and-pharmaceutical manufacturing government-and-public-sector

Context

KillSwitch is a ransomware family known for encrypting files and demanding payment for decryption keys. It typically targets high-value industries and has been observed globally in sophisticated attacks.

Detection coverage

  • 2 YARA rules

Detection rules

  • SIGNATURE_BASE_BKDR_Xzutil_Killswitch_CVE_2024_3094_Mar24_1 (yara-rule)
  • ESET_Mozi_Killswitch (yara-rule)