logo

Medusa Ransomware Leverages Signed Malicious Driver to Bypass EPP/EDR

ID: ea094895-6e07-532c-b376-be70a1f9f096

STIX ID: report--ea094895-6e07-532c-b376-be70a1f9f096

Feed Name: Halcyon Blog

Threat Score
75/100

Date Published: 2025-03-31

Date Updated: 2026-04-28

...
...

Researchers observed the Medusa RaaS operation deploying a revoked, signed malicious driver called ABYSSWORKER (smuol.sys) via a HeartCrypt-packed loader to perform BYOVD attacks that remove EDR notification callbacks and blind security products; multiple samples signed with likely stolen certificates were found on VirusTotal (Aug 2024–Feb 2025). The report also notes exploitation of a vulnerable ZoneAlarm kernel driver to gain elevated privileges and persistent RDP access; recommended mitigations include updating drivers, restricting administrative installs, and detecting BYOVD behaviors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.