Killall

Category: ransomware · Aliases: HackTool.KillAll, Trojan.KillAV, Script.Wiper · Sample count (EMBER 2018): 1 · Enrichment: insufficient_information · Updated: 2026-07-02T07:05:10Z
Category: RansomwareActor: Unknown / CybercriminalIndustry: Global / OpportunisticMotivation: Opportunistic

Overview

Executive Summary

KillAll is a classification for malicious scripts, utilities, or "HackTools" specifically designed to aggressively terminate running processes across an operating system. While system administrators use legitimate tools to manage processes, threat actors deploy "KillAll" variants defensively to disable endpoint security software (AV/EDR), or offensively as a crude "wiper" to induce immediate system instability and denial of service.

Infection Vector and Technical Capabilities

KillAll is not a self-propagating virus. It is a tactical tool deployed *after* an attacker has gained a foothold, typically used immediately prior to launching a primary payload (like ransomware) or during the exfiltration phase to disable monitoring. Its execution is straightforward but highly disruptive:

Threat Assessment

The execution of a "KillAll" script is a critical, "break-glass" security incident. It indicates an active, hands-on-keyboard adversary (or a highly automated ransomware strain) is preparing the environment for a catastrophic attack by systematically blinding the organization's defensive and monitoring capabilities.

Incident Response and Remediation

Known aliases

Threat reports may refer to this family under multiple names:

MITRE ATT&CK Techniques

This family has been observed using the following ATT&CK techniques: T1562.001 T1489

Generated Detections (Boilerplate)

These YARA and Sigma rules are auto-generated based on the family name and aliases. They must be heavily tuned before deployment in a production environment.

YARA Rule

rule MALWARE_WIN_KILLALL {
    meta:
        description = "Detects Killall (ransomware)"
        author = "SystemHelpdesk Boilerplate Generator"
        date = "2026-07-06"
    strings:
        $s1 = "killall" ascii wide nocase
        $s2 = "hacktool.killall" ascii wide nocase
        $s3 = "trojan.killav" ascii wide nocase
        $s4 = "script.wiper" ascii wide nocase
    condition:
        uint16(0) == 0x5a4d and any of them
}

Sigma Rule

title: Suspicious Killall Activity
id: 9c09f19d809e8e166b92905783778d40
status: experimental
description: Detects generic indicators of the killall malware family.
logsource:
    category: process_creation
    product: windows
detection:
    selection:
        Image|endswith:
            - '\cmd.exe'
            - '\powershell.exe'
        CommandLine|contains:
            - "*killall*"
            - "*hacktool.killall*"
            - "*trojan.killav*"
            - "*script.wiper*"
    condition: selection
level: medium

References & External Analysis

Frequently Asked Questions

How do I remove the Killall Ransomware from Windows?

Manual removal of Killall is highly discouraged as it may leave persistence mechanisms intact. We recommend disconnecting the device from the internet and utilizing a professional incident response service or enterprise-grade EDR software to conduct a full forensic sweep.

Is Killall a virus or a Ransomware?

Killall is classified as a Ransomware. Unlike traditional viruses that infect files, modern malware like Killall typically operates as a standalone payload designed to compromise systems, steal data, or deploy secondary stage implants.

What are the main symptoms of a Killall infection?

Symptoms of Killall can include unexpected system slowness, unauthorized outbound network traffic to unknown IP addresses, disabled security software, and suspicious background processes running from AppData or Temp directories.

Related Families (Category: ransomware)

Explore other malware families in the same category:

Protect Your Network Against Ransomwares

Want to prevent Killall and similar threats from compromising your organization? Read our comprehensive defensive guide: Ransomware Protection Guide.

Need help with an active incident? Published by the SystemHelpdesk team.

Machine-readable

Get this profile as JSON: https://jordanricky1604-ship-it.github.io/malware-families-catalog/api/killall.json

Ecosystem & Interactive Environments

This profile is part of the Malware Families Catalog, a public dataset of 2,899 malware families. The catalog is also published across our ecosystem: Hugging Face, Kaggle, Zenodo, Replit, StackBlitz, CodeSandbox, and CodePen.