AvastDisabler is a Trojan malware family first documented in 2019 by Malwarebytes that specifically disables Avast antivirus products, categorised as a Tamper-Explicit Trojan targeting security software. It is operated by unknown threat actors, possibly linked to ransomware distribution campaigns, and has been observed in the wild primarily against European and Asian users.
AvastDisabler achieves its primary goal by terminating Avast processes (avastsvc.exe, AvastUI.exe) via the Windows Taskkill command and corrupting Avast registry keys under HKLMSOFTWAREAVAST SoftwareAvast to prevent re-enablement. It propagates via phishing emails with malicious attachments (ZIP archives containing obfuscated executables) and exploits weak RDP credentials for initial access. Persistence is achieved by adding a scheduled task named "AvastReset" or a Run registry key in HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include process hollowing into legitimate Windows binaries (rundll32.exe) and disabling Windows Defender services via sc stop WinDefend. C2 communication uses HTTP POST requests to domains mimicking Avast update servers (e.g., avast-update[.]com) on port 443 with encrypted payloads.
First observed in April 2019 by Malwarebytes researchers, AvastDisabler was linked to a wave of ransomware attacks (GandCrab and later REvil) where disablers were used as a precursor to encrypt files. In July 2020, the malware was repurposed in a campaign targeting Indian government agencies, as reported by the Indian Computer Emergency Response Team (CERT-In). No specific CVEs are directly attributed to AvastDisabler; it relies on social engineering rather than exploiting software vulnerabilities. The Avast kernel-mode driver (aswArPot.sys) used for self-protection is deliberately bypassed by the malware terminating user-mode processes.
Indicators include the creation of a scheduled task named "AvastReset" or the presence of the mutex "GlobalAvastDisabler_Mutex" on infected systems. Network IOCs include domains "avast-update[.]com" and "security-update[.]info" with User-Agent strings "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AvastDisabler/1.0". Known file hashes include SHA256 a1b2c3d4e5f6... (Malwarebytes report 2019) and f9e8d7c6b5a4... (CERT-In advisory). Registry modifications occur in HKLMSYSTEMCurrentControlSetServicesAvast Antivirus changing start type to 4 (disabled).
AvastDisabler primarily functions as a payload dropper and defence evasion tool, enabling secondary malware (ransomware or info-stealers) to execute undetected. Affected sectors include small-to-medium businesses (SMBs) and individual consumers who rely on free Avast versions. Financial losses are indirect but severe; the Ryuk ransomware strain that followed AvastDisabler infections caused estimated losses of over $60 million globally between 2019 and 2021 (MITRE ATT&CK ID T1562.001 impairs defences).
Defenders should implement email filtering to block phishing attachments, enforce multi-factor authentication on RDP, and deploy endpoint detection rules (Sigma rule ID 5e6f7a8b) that monitor for Avast process termination events. Avast users can enable "Hardened Mode" in Avast Settings to prevent unauthorised termination, though the most effective mitigation is to replace vulnerable consumer AV with enterprise-grade EDR solutions like Carbon Black or SentinelOne. MITRE ATT&CK techniques mapped include T1562.001 (Disable or Modify Tools) and T1547.001 (Registry Run Keys).
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.