Shedding light on the ABYSSWORKER driver
ID: 8a8b3151-4a0e-54f1-99ce-6f3745360ef2
STIX ID: report--8a8b3151-4a0e-54f1-99ce-6f3745360ef2
Feed Name: Elastic Security Labs
This report provides an in-depth technical analysis of ABYSSWORKER, a malicious 64-bit Windows kernel driver (smuol.sys) signed with revoked/stolen certificates and used alongside a HEARTCRYPT-packed loader to disable EDR products and enable deployment of MEDUSA ransomware; it details initialization, client protection, IOCTL command set for disabling defenses and manipulating files/processes/drivers, API-loading mechanisms, mitigation notes, and includes YARA and observable hashes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
