typetechniquefamily9d2ca3confidencehighcreated2026-08-04updated2026-08-04defense-evasionanti-vmanti-debugmitre-attckregistrymalware-family

av-registry-exclusion-spray

Defense-evasion technique: systematically add directory/file exclusions to the registry hives of every major endpoint-security product on the victim machine, including both Western and Chinese vendors. Reduces the probability that any installed AV will scan the staging directory or quarantine the payload. Observed in a lightweight .NET Framework 4.6.2 stage-1 dropper (8f288492) distributed via Amadey. ^[/intel/analyses/8f28849296f4c10a3271aec35441bc7421be693be966f749cf50120730adb348.html]

What It Does

The malware iterates a hardcoded list of AV product names and writes exclusion registry keys under each vendor's hive. This is a "spray" approach — instead of targeting only Windows Defender (the most common target), it covers eleven vendors to maximize survivability on diverse endpoint stacks.

Observed Vendor List

Vendor Registry Path (observed) Notes
Windows Defender SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths Standard Microsoft path
ESET SOFTWARE\ESET\Exclusions European NOD32/Endpoint
AVG SOFTWARE\AVG\Exclusions Acquired by Avast; still distinct hive
Bitdefender SOFTWARE\Bitdefender\Exclusions Romanian vendor
Kaspersky SOFTWARE\KasperskyLab\Exclusions Russian vendor
Norton SOFTWARE\Norton\Exclusions Symantec legacy
McAfee SOFTWARE\McAfee\Exclusions Intel/Trellix legacy
Tencent SOFTWARE\Tencent\TAV\Exclusions Chinese endpoint (Tencent Anti-Virus)
Avast SOFTWARE\AVAST Software\Avast\Exclusions Czech vendor
360 Safe SOFTWARE\360Safe\scan\Trusted Chinese vendor; path is Trusted not Exclusions
Huorong (火绒) SOFTWARE\Huorong\Sysdiag\WhiteList Chinese vendor; misspelled Mhuorong in binary

Code Pattern

The exclusion list is stored as a static string array in the .NET class X7Y9Z.Q8W4K, loaded via InitAvList, then written via Registry.SetValue in a loop inside AddExclusions. The target path (pathToExclude) is typically the staging directory where core.exe will be dropped. ^[/intel/analyses/8f28849296f4c10a3271aec35441bc7421be693be966f749cf50120730adb348.html]

Detection

  • Registry event logs (Sysmon Event ID 13, Windows 4657) showing rapid sequential SetValue operations across multiple vendor Exclusions or WhiteList keys within the same process lifetime.
  • Process creation of a .NET binary immediately followed by powershell.exe with Add-MpPreference -ExclusionPath and Set-MpPreference -DisableRealtimeMonitoring $true.
  • The 360Safe\scan\Trusted and Huorong\Sysdiag\WhiteList paths are high-signal indicators — legitimate software rarely writes there.

Defensive Countermeasures

  • Tamper-protection on AV registry hives (modern ESET, Kaspersky, and Defender have this enabled by default; the spray will fail on these if tamper protection is active).
  • Behavioral detection: flag any process that writes to more than two distinct AV vendor registry hives within a 5-second window.

Pages Where Observed

  • 9d2ca3 — Fifth confirmed build morph under this contested OpenCTI label; the 11-vendor spray is unique to this sibling (8f288492).
  • Related but narrower: defender-exclusion-via-powershell — prior samples only targeted Windows Defender via PowerShell.