logo

Driver-Based Ransomware Tactics

ID: 0eb38bea-799c-5a6d-846e-9fba5a4311cf

STIX ID: report--0eb38bea-799c-5a6d-846e-9fba5a4311cf

Feed Name: Canary Trap

Threat Score
75/100

Date Published: 2025-03-31

Date Updated: 2026-05-13

Author: Canary Trap

...
...

The report describes Medusa using a malicious, signed driver (ABYSSWORKER / smuol.sys) in a BYOVD attack—delivered via a HeartCrypt-packed loader and masquerading as a CrowdStrike component—to disable endpoint detection and response tools and enable stealthy ransomware deployment; it also details RansomHub’s use of the Betruger backdoor for reconnaissance and privilege escalation, reflecting a trend toward low-level, evasive tactics in modern ransomware operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.