Site icon WinCert

CrowdStrike unveils the “Terminator” who can bypass most popular malware protection apps

<p>Andrew Harris&comma; the Global Senior Director at CrowdStrike cybersecurity company recently unveiled new information about the new Endpoint Detection and Response &lpar;EDR&rpar; evasion tool named &&num;8220&semi;Terminator&period;&&num;8221&semi; This tool has been gaining popularity on the Russian Anonymous Marketplace &lpar;RAMP&rpar; under the promotion of a threat actor named &&num;8220&semi;Spyboy&period;&&num;8221&semi; The campaign appears to be started around May 21&comma; raising concerns in the cybersecurity community&period;<&sol;p>&NewLine;<p><img class&equals;"alignnone size-full wp-image-4335" src&equals;"https&colon;&sol;&sol;www&period;wincert&period;net&sol;wp-content&sol;uploads&sol;2021&sol;09&sol;hacker-6512174&lowbar;640&period;jpg" alt&equals;"" width&equals;"640" height&equals;"400" &sol;><&sol;p>&NewLine;<p>The author behind the alias &&num;8220&semi;Spyboy&&num;8221&semi; claims that the Terminator tool can effectively neutralize twenty-three EDR and antivirus controls&comma; including the most popular malware protection applications from Microsoft&comma; Sophos&comma; CrowdStrike&comma; AVG&comma; Avast&comma; ESET&comma; Kaspersky&comma; McAfee&comma; BitDefender&comma; Malwarebytes&comma; and others&period; With prices ranging from &dollar;300 for a single bypass to &dollar;3&comma;000 for an all-in-one bypass&comma; the tool is being promoted as a powerful weapon for cyber protectors&period;<&sol;p>&NewLine;<p>CrowdStrike has analyzed the power of the Terminator EDR evasion tool&period; They&&num;8217&semi;ve discovered that the software generates a seemingly legitimate and signed driver file called Zemana Anti-Malware&comma; which exploits a known security vulnerability tracked under the identification &&num;8220&semi;<a href&equals;"https&colon;&sol;&sol;cve&period;mitre&period;org&sol;cgi-bin&sol;cvename&period;cgi&quest;name&equals;2021-31728" target&equals;"&lowbar;blank" rel&equals;"noopener">CVE-2021-31728<&sol;a>&&num;8221&semi; However&comma; it&&num;8217&semi;s worth saying that executing the Terminator tool requires elevated privileges &lpar;run as administrator&rpar;&period; What is surprising is that out of the 70 vendors who analyzed it on VirusTotal&comma; only Elastic was able to identify the file as malicious&comma; while the rest failed to do so&period;<&sol;p>&NewLine;<p>Andrew Harris also said that the Terminator tool uses a strategy of Bring Your Own Vulnerable Driver &lpar;BYOVD&rpar; campaigns&comma; which threat actors commonly use&period;  Once the Terminator software is started under administrative privileges the binary proceeds to write a legitimate and signed driver file &lpar;Zemana Anti-Malware&rpar; to the <strong>C&colon;&bsol;Windows&bsol;System32&bsol;drivers&bsol;<&sol;strong> directory&period; The driver file is then assigned a random name consisting of 4 to 10 characters&comma; like <strong>zamguard64&period;sys<&sol;strong> or <strong>zam64&period;sys<&sol;strong>&period; The driver file is signed by &&num;8220&semi;Zemana Ltd&&num;8221&semi; and can be identified under the following thumbprint&colon; <strong>96A7749D856CB49DE32005BCDD8621F38E2B4C05<&sol;strong>&period;<&sol;p>&NewLine;<p>Once the Terminator software has written the driver file to the system&comma; it loads the driver and terminates user-mode processes associated with antivirus and EDR software&period;<&sol;p>&NewLine;<p>During a demonstration&comma; the company showcased the Terminator tool&&num;8217&semi;s effectiveness by successfully disabling CrowdStrike Falcon EDR&period;<&sol;p>&NewLine;<p>The emergence of the Terminator tool and its endorsement by Spyboy on the Russian Anonymous Marketplace raises concerns within the cybersecurity community&period; In order to protect your system&comma; system administrators are advised to continuously update their security measures&comma; and leverage proactive threat intelligence in order to combat evolving threats&period;<&sol;p>&NewLine;

Exit mobile version