> ## Content Index
> Fetch the complete content index at: https://darkwebinformer.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Alleged sale of Antivirus/Endpoint Detection and Response Killer
- URL: https://darkwebinformer.com/alleged-sale-of-antivirus-endpoint-detection-and-response-killer/
- Published: 2025-12-25T16:02:54.000Z
- Updated: 2025-12-25T23:25:17.000Z
- Author: Dark Web Informer
- Tags: Malware

<!DOCTYPE html> 

Dark Web Informer - Cyber Threat Intelligence

BREACH ALERTS

# Alleged sale of Antivirus/Endpoint Detection and Response Killer

📅 December 25, 2025 - 12:16:09 AM 

🦠 Malware 

⚠️ Low Severity 

Affected Organization

Unknown

Website

Unknown

Threat Actor

Kill3r

### Incident Overview

The threat actor claims to be selling an AV/EDR Killer malware tool advertised as capable of disabling and removing multiple enterprise security products. The malware allegedly targets major antivirus and endpoint detection and response (EDR) solutions commonly deployed in corporate environments. 

According to the threat actor's advertisement, the tool claims to be effective against the following security products: 

- SentinelOne
- Microsoft Defender for Endpoint (MDE)
- Sophos Endpoint Security
- ESET Endpoint Security
- Trend Micro
- Avast Business
- Avira Pro
  
The offering is advertised as including code, a builder tool, and a Microsoft-signed driver dated 2025\. The threat actor claims the tool has been tested against the listed security products. The price is listed at $3,000, with payment details provided via a TOX messaging ID. 

Tools designed to disable security software are commonly used by ransomware operators and other threat actors to evade detection and maintain persistence on compromised systems. Such tools often exploit legitimate drivers or use code-signing certificates to bypass security controls. 

### Image Preview

[ ![Screenshot of alleged AV/EDR Killer malware sale listing](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2025/12/9873287235872638523523.png) ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2025/12/9873287235872638523523.png) 

🔒

### Unlock Full Breach Intelligence

Premium subscribers gain access to PLUS, PRO, or ELITE features, including breach claim URLs and fully unredacted threat and ransomware feeds with no blur, along with leak and breach coverage, 500+ onion and clearnet resources, uptime monitoring, high-resolution watermark-free images, and more. 

[Subscribe Now](https://darkwebinformer.com/#/portal/signup) [Subscribe with Crypto](https://darkwebinformer.com/crypto-payments/) 

🔬

### API Access for Researchers & Security Teams

SOC teams, researchers, and security professionals can integrate Dark Web Informer's threat intelligence directly into their workflows via API. Access real-time breach data, threat feeds, and monitoring capabilities programmatically. 

[Learn About API Access](https://darkwebinformer.com/api-details/) 

Dark Web Informer © 2025 | Cyber Threat Intelligence | [DarkWebInformer.com](https://darkwebinformer.com/)