Skip to content
  Thursday 15 January 2026
Trending
April 3, 2025Cybersecurity Intern March 6, 2024Cybersecurity Consultant July 12, 2025Lead Cybersecurity Asset Management Engineer December 10, 2024Data-Driven Businesses Rediscover Benefits of Faxing Software – SmartData Collective May 14, 2025Mid-Level Cybersecurity Engineer March 17, 2025<h3>GitHub Repositories and Secrets Hit by Supply Chain Attack!</h3> January 1, 2024The Importance of Spam Prevention for Data-Driven Businesses January 3, 2022Top 8 Best Free Audio Equalizers For Windows 10/11 in 2022 November 14, 2023Data Privacy & Cybersecurity Lawyer June 20, 2024Sr. Cybersecurity Engineer
Mister Cybersecurity
  • Home
  • News
    • Daily Update
    • Industry News
    • Threat Advisories
  • Simulators
    • Exam Simulators
      • CompTIA Security+
      • CompTIA Advanced Security Practitioner (CASP+)
      • Certified Ethical Hacker (CEH)
      • Certified Information Systems Security Professional (CISSP)
      •  Certified Information Systems Auditor (CISA)
      • Certified Information Security Manager (CISM)
      • Systems Security Certified Practitioner (SSCP)
      • GIAC Security Essentials Certification (GSEC)
      • GIAC Certified Incident Handler (GCIH)
      • Offensive Security Certified Professional (OSCP)
    • Training Simulators
      • Blue Team Simulator
      • Red Team Simulator
  • Tools
    • VulnVisor – Vulnerability Explorer
    • Takedown Request Generator
    • Dark Coder – Auto Code Generator
    • SKY VPN
  • Courses
    • SQL Injection Fundamentals with Kali Linux
    • Web Application Hacking
    • Session Hijacking
    • DoS & DDoS Attacks for Beginners
    • Cryptography for Cybersecurity & Hacking
    • Evasion Tactics – IDS, Firewalls & Honeypots
  • Tutorials
    • Security
    • Malware
    • Virus
    • Social Media Security
    • Wireless Security
    • Linux
    • Privacy
    • Windows
      • Windows 11
    • Android
    • iPhone
  • Software
    • Antivirus
    • Android APK
    • Best Free VPN
    • Encryption Tools
    • Hacking Tools
    • Network Utilities
    • Pentesting Tools
    • Themes and Skins
    • Operating Systems
  • More
    • Alternative Sites
    • Cloud Storage
    • Chrome OS
    • Encryption
    • Email Security
    • Ethical Hacking Books
    • Firewall
    • Hacking
    • Web
    • Ransomware
  • Careers
  • Store
  • Account
    • Log In
    • Your Profile
    • Membership Billing
    • Membership Account
Mister Cybersecurity
Mister Cybersecurity
  • Home
  • News
    • Daily Update
    • Industry News
    • Threat Advisories
  • Simulators
    • Exam Simulators
      • CompTIA Security+
      • CompTIA Advanced Security Practitioner (CASP+)
      • Certified Ethical Hacker (CEH)
      • Certified Information Systems Security Professional (CISSP)
      •  Certified Information Systems Auditor (CISA)
      • Certified Information Security Manager (CISM)
      • Systems Security Certified Practitioner (SSCP)
      • GIAC Security Essentials Certification (GSEC)
      • GIAC Certified Incident Handler (GCIH)
      • Offensive Security Certified Professional (OSCP)
    • Training Simulators
      • Blue Team Simulator
      • Red Team Simulator
  • Tools
    • VulnVisor – Vulnerability Explorer
    • Takedown Request Generator
    • Dark Coder – Auto Code Generator
    • SKY VPN
  • Courses
    • SQL Injection Fundamentals with Kali Linux
    • Web Application Hacking
    • Session Hijacking
    • DoS & DDoS Attacks for Beginners
    • Cryptography for Cybersecurity & Hacking
    • Evasion Tactics – IDS, Firewalls & Honeypots
  • Tutorials
    • Security
    • Malware
    • Virus
    • Social Media Security
    • Wireless Security
    • Linux
    • Privacy
    • Windows
      • Windows 11
    • Android
    • iPhone
  • Software
    • Antivirus
    • Android APK
    • Best Free VPN
    • Encryption Tools
    • Hacking Tools
    • Network Utilities
    • Pentesting Tools
    • Themes and Skins
    • Operating Systems
  • More
    • Alternative Sites
    • Cloud Storage
    • Chrome OS
    • Encryption
    • Email Security
    • Ethical Hacking Books
    • Firewall
    • Hacking
    • Web
    • Ransomware
  • Careers
  • Store
  • Account
    • Log In
    • Your Profile
    • Membership Billing
    • Membership Account
Mister Cybersecurity
  Industry News  Medusa Ransomware Disables Anti-Malware with Stolen Certificates – Beware!
Industry News

Medusa Ransomware Disables Anti-Malware with Stolen Certificates – Beware!

SecuredyouadmSecuredyouadm—March 21, 20250
FacebookTwitterPinterestLinkedInTumblrRedditVKWhatsAppEmail
More stories

US Judge Approves Landmark $177M AT&T Data Breach Settlement

June 23, 2025

Hackers Now Using AI Code Editors to Sneak in Malicious Code with ‘Rules File Backdoor’ Attack

March 18, 2025

Netskope Boosts Cloud Security with Dasera Acquisition

October 16, 2024

Enhancing KYC Programs by Evaluating Banking Product Risks

November 7, 2024



On March 21, 2025, Elastic Security Labs discovered that threat actors associated with the Medusa ransomware-as-a-service (RaaS) operation were using a malicious driver called ABYSSWORKER in a bring your own vulnerable driver (BYOVD) attack. This attack was specifically designed to disable anti-malware tools. The encryptor was delivered through a loader packed using a packer-as-a-service (PaaS) known as HeartCrypt.

The ABYSSWORKER driver, named “smuol.sys,” was found to mimic a legitimate CrowdStrike Falcon driver. It was signed using likely stolen, revoked certificates from Chinese companies. This allowed the malware to bypass security systems without raising any alarms. The driver was previously documented by ConnectWise in January 2025 as “nbwdv.sys.”

Once ABYSSWORKER is initialized, it adds the process ID to a list of global protected processes and listens for incoming device I/O control requests. These requests are then dispatched to appropriate handlers based on I/O control code, enabling the tool to terminate or disable endpoint detection and response (EDR) systems.

Of particular interest is the ability of ABYSSWORKER to blind security products by removing registered notification callbacks. This technique has also been observed in other EDR-killing tools like EDRSandBlast and RealBlindingEDR. The findings align with a report from Venak Security about threat actors exploiting a vulnerable kernel driver associated with Check Point’s ZoneAlarm antivirus software in a BYOVD attack to gain elevated privileges.

The use of custom malware like ABYSSWORKER and Betruger by ransomware groups points to a shift in tactics. These tools allow threat actors to bypass security measures and gain full control of infected systems, facilitating data exfiltration and further exploitation. The cybersecurity landscape continues to evolve, emphasizing the importance of robust security measures to protect against increasingly sophisticated threats.



Source link

FacebookTwitterPinterestLinkedInTumblrRedditVKWhatsAppEmail

Securedyouadm

10 Network Pentest Findings IT Teams Miss!
Taiwan’s Critical Infrastructure Under Attack by UAT-5918 with Web Shells and Open-Source Tools
Related posts
  • Related posts
  • More from author
Industry News

5 Reasons AI-Driven Business Need Dedicated Servers – SmartData Collective

October 14, 20250
Industry News

The Future of Cyberthreat Sharing Post-CISA 2015: What’s Next?

October 1, 20250
Industry News

Meta Strikes $14.2B AI Deal with CoreWeave for Cutting-Edge Infrastructure

October 1, 20250
Load more
Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Read also
Careers

Cybersecurity Analyst

January 14, 20260
Careers

Lead Cybersecurity – SOX

January 14, 20260
Careers

Senior Cloud Security Engineer, AVP – BXTI Cybersecurity

January 14, 20260
Careers

Sr. Cybersecurity Analyst, Compliance

January 14, 20260
Careers

Cybersecurity Analyst

January 14, 20260
Careers

CYBERSECURITY ANLST SR

January 14, 20260
Load more
Stay Social!
192Likes
4,500Followers
13Subscribers
46Followers
Recent posts
  • Cybersecurity Analyst
  • Lead Cybersecurity – SOX
  • Senior Cloud Security Engineer, AVP – BXTI Cybersecurity
  • Sr. Cybersecurity Analyst, Compliance
  • Cybersecurity Analyst

    # TRENDING

    how old is my computerhow old is my dell laptophow old is my HP laptophow old is my laptophow old is my toshiba laptophow to find computer ageverify computer agestar wars theme wallpapersThe Best Hacking Bookswiresharkusb device not found windows 10/11usb device not recognized windows 10/11 errorWhat is AIGPUSnifferuTorrentvulnerability scanner downloadWifi Hacking SoftwareWifi Hacking Appsolved windows 10/11 usb device not recognizedstar wars windows 7 theme downloadTwitter Account Security
    © Copyright Mister Cybersecurity LLC 2023, All Rights Reserved
    • About
    • Contact
    • Privacy
    • ToS
    • Disclosures