Exposed: Medusa Ransomware’s Stealth Attack Using Stolen Certificates to Cripple Security Defenses


# Medusa Ransomware Operators Deploy ABYSSWORKER Driver to Disable Security Tools

Security researchers have identified that Medusa ransomware operators are utilizing a malicious driver called ABYSSWORKER in sophisticated bring-your-own-vulnerable-driver (BYOVD) attacks specifically designed to disable anti-malware protections.

According to Elastic Security Labs, a recent Medusa ransomware attack delivered its encryption payload via a loader packed with HeartCrypt, a packer-as-a-service solution. This loader was deployed alongside a driver named “smuol.sys” that mimics CrowdStrike Falcon’s legitimate “CSAgent.sys” driver.

The ABYSSWORKER driver, detected on VirusTotal between August 2024 and February 2025, is signed with stolen, revoked certificates from Chinese companies. This digital signing provides a false appearance of legitimacy that helps bypass security systems.

Once activated, ABYSSWORKER adds process IDs to a protected list and responds to I/O control requests that enable various malicious capabilities, including:
– File manipulation
– Process and driver termination
– Removal of security notification callbacks
– System thread termination
– Security product disabling

The driver’s ability to remove registered notification callbacks is particularly concerning, as this technique effectively blinds endpoint detection and response (EDR) systems—a method also employed by other EDR-killing tools like EDRSandBlast.

In a separate but related development, Venak Security reported threat actors exploiting a legitimate but vulnerable kernel driver from Check Point’s ZoneAlarm antivirus to gain elevated privileges and disable Windows security features. Check Point has since patched this vulnerability.

Additionally, researchers have linked the RansomHub (also known as Greenbottle and Cyclops) ransomware operation to a previously undocumented backdoor called Betruger. This multi-function tool provides capabilities including screenshotting, keylogging, credential dumping, and data exfiltration—representing an unusual departure from typical ransomware tactics that rely on publicly available tools.

Share This Article