Netskope Threat Labs

KillAV

ATP Sandbox Adv. HeuristicsAV

KillAV is a detection name for tools that terminate antivirus processes and security services on infected systems. Disabling endpoint defenses is a standard pre-encryption and pre-exfiltration step in ransomware and espionage intrusions, because blinded agents stop reporting criminal activity. Detections under this name indicate that malware attempted to tamper with security tooling, which is itself strong evidence of a deliberate intrusion.

First seen
February 2022
Last seen
October 2026
KillAvKillav
Alert Name
ByteCode-MSIL.Trojan.KillAV
DeepScan:Generic.KillAV.4297DF1B
Dropped:Trojan.Vbs.Killav.V
Gen:Variant.KillAV.16
Gen:Variant.KillAV.17
Gen:Variant.KillAV.23
Gen:Variant.KillAV.26
Gen:Variant.KillAV.34
Gen:Variant.KillAV.35
Gen:Variant.KillAV.47