AuKill - Tool

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
February 9, 2026
Last Seen
June 30, 2026

AuKill is a tool tracked across 2 threat clusters and 2 intelligence report mentions on ThreatCluster. First observed February 9, 2026; most recent activity June 30, 2026.

Related Threat Clusters

  • BYOVD Technique Enables Attackers to Disable Security Tools

    Attackers are increasingly using the Bring Your Own Vulnerable Driver (BYOVD) technique to disable antivirus (AV) and endpoint detection and response (EDR) tools. This method exploits flaws in trusted Windows drivers,…

    2 articles · Updated July 1, 2026
  • Black Basta Ransomware Integrates BYOVD Defense Evasion Technique

    The Black Basta ransomware gang has incorporated a bring-your-own-vulnerable-driver (BYOVD) defense evasion component within its ransomware payload. This technique, which typically involves separate tools to disable…

    9 articles · Updated February 9, 2026

Recent Intelligence Reports

  • The BYOVD Epidemic: How Attackers Are Weaponizing Trusted Windows Drivers to Kill Security — Security · June 30, 2026
  • Black Basta Bundles BYOVD With Ransomware Payload — Darkreading · February 9, 2026

CVSS v3.1 Breakdown