
Windows Defender-Killer Tool Folded Into XRed RAT Dropper
A commodity Defender-disabling hacktool shares its YARA signature with a Synaptics-driver-disguised RAT dropper, showing the defense-evasion code was built directly into the implant rather than dropped separately. The overlap, paired with matching imphashes and dynamic-DNS beaconing, points to a single build pipeline behind the cluster.
A commodity tool built to switch off Windows Defender with one click has turned up inside the build of a remote-access-trojan dropper — not dropped alongside it, but sharing the same crowdsourced YARA signature. The standalone hacktool, tracked publicly as DefenderControl and carried in this set as 1ef6c1a4dfdc39b63bfe650ca81ab89510de6c0d3d7c608ac5be80033e559326, and a Synaptics-driver-themed dropper that sandboxing names as the XRed RAT,…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read