logo

Shedding light on the ABYSSWORKER driver

ID: 8a8b3151-4a0e-54f1-99ce-6f3745360ef2

STIX ID: report--8a8b3151-4a0e-54f1-99ce-6f3745360ef2

Feed Name: Elastic Security Labs

Threat Score
78/100

Date Published: 2025-03-20

Date Updated: 2026-04-27

...
...

This report provides an in-depth technical analysis of ABYSSWORKER, a malicious 64-bit Windows kernel driver (smuol.sys) signed with revoked/stolen certificates and used alongside a HEARTCRYPT-packed loader to disable EDR products and enable deployment of MEDUSA ransomware; it details initialization, client protection, IOCTL command set for disabling defenses and manipulating files/processes/drivers, API-loading mechanisms, mitigation notes, and includes YARA and observable hashes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.