A malicious driver known as ABYSSWORKER has been used by the threat actors behind the Medusa ransomware-as-a-service (RaaS) operation as part of a bring your own vulnerable driver (BYOVD) attack that aims to disable anti-malware software.
According to Elastic Security Labs, it saw a Medusa ransomware assault that used a loader packaged using the HeartCrypt packer-as-a-service (PaaS) to deploy the encryptor.
According to a report from the company, this loader was used in conjunction with a driver issued with a revoked certificate from a Chinese vendor called ABYSSWORKER. The loader installs itself on the victim’s computer and then targets and silences several EDR suppliers.
“Smuol.sys,” the aforementioned driver, imitates a genuine CrowdStrike Falcon driver read more about Medusa Ransomware Uses Malicious Driver to Disable Anti-Malware with Stolen Certificates.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
