TangleCrypt Windows Packer with Ransomware Payloads Evades EDR Using ABYSSWORKER Driver
ID: 014cfa72-7e4b-5e05-b45c-bfd0970b3f06
STIX ID: report--014cfa72-7e4b-5e05-b45c-bfd0970b3f06
Feed Name: cybersecurityNews.com
Threat Score
TangleCrypt is a newly observed Windows packer used in a September 2025 Qilin ransomware incident that conceals payloads through layered base64 encoding, LZ78 compression and XOR encryption; it supports in-process and suspended-child process execution modes and was used to deliver the STONESTOP EDR‑killer and ABYSSWORKER driver to disable security products before encryption.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
