Driver-Based Ransomware Tactics
ID: 0eb38bea-799c-5a6d-846e-9fba5a4311cf
STIX ID: report--0eb38bea-799c-5a6d-846e-9fba5a4311cf
Feed Name: Canary Trap
Threat Score
The report describes Medusa using a malicious, signed driver (ABYSSWORKER / smuol.sys) in a BYOVD attack—delivered via a HeartCrypt-packed loader and masquerading as a CrowdStrike component—to disable endpoint detection and response tools and enable stealthy ransomware deployment; it also details RansomHub’s use of the Betruger backdoor for reconnaissance and privilege escalation, reflecting a trend toward low-level, evasive tactics in modern ransomware operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
