Cyber Security News

Hackers Advertised VOID ‘AV Killer’ with Kernel-level Termination Claims

The cybercriminal threat actor known as Crypt4You has recently emerged on underground forums and dark web marketplaces, advertising a sophisticated tool named VOID KILLER.

This malicious software operates as a kernel-level antivirus and endpoint detection response (EDR) process killer, designed to evade and neutralize security defenses.

The tool is being marketed as an alternative to traditional crypters, representing a significant shift in how cybercriminals approach defense bypass mechanisms.

By targeting the core of operating systems, VOID KILLER attempts to eliminate protective barriers that organizations rely on to detect and stop malicious activities.

The emergence of VOID KILLER highlights an escalating threat landscape where attackers are investing in advanced tools to compromise enterprise environments.

Unlike traditional malware that simply encrypts code, this kernel-level solution directly terminates security processes before they can respond to threats.

Security researchers have documented that the tool directly challenges modern defensive architectures, particularly those relying on behavioral detection and real-time monitoring capabilities.

KrakenLabs researchers and analysts identified and documented the threat after examining the tool’s advertising materials and claimed capabilities.

VOID KILLER Analysis

The analysis revealed that VOID KILLER represents a dangerous evolution in anti-detection technology, offering cybercriminals the means to operate with reduced oversight within compromised systems.

Kernel-level termination represents the most critical technical aspect of VOID KILLER’s functionality. Operating at the kernel level means the tool executes with the highest system privileges, allowing it to bypass standard user-mode protections.

According to the threat intelligence findings, VOID KILLER claims to terminate Windows Defender and approximately fifty consumer-grade antivirus solutions instantly, reportedly with zero detection at both scan and runtime stages.

The tool employs polymorphic build techniques, generating fresh file hashes with each compilation to evade signature-based detection systems.

Additionally, it incorporates automatic User Account Control (UAC) bypass mechanisms, enabling it to escalate privileges without triggering security alerts.

The payload-agnostic architecture allows operators to inject any executable file, making VOID KILLER compatible with various malware families.

Notably, the seller offers additional variants targeting enterprise solutions like CrowdStrike and SentinelOne, sold separately for enhanced market penetration.

The threat actor prices custom VOID KILLER builds at three hundred dollars per instance, accepting Bitcoin, Ethereum, Litecoin, and Monero. A demonstration video shared by Crypt4You further validates the tool’s destructive capabilities.

Organizations using Windows Defender, consumer antivirus software, and even advanced EDR solutions face heightened risk exposure.

The advent of VOID KILLER underscores the necessity for defense-in-depth strategies and kernel-level security implementations to counter emerging threats effectively.

Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

2 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

12 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

13 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

13 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

13 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

13 hours ago