216.73.216.226

Shedding light on the ABYSSWORKER driver

· Published 20/03/2025 15:17 · Modified 20/03/2025 16:13

Export JSON

Essential information

Published
20/03/2025 15:17
Modified
20/03/2025 16:13
Tags
2025-03-20 abyssworker driver edr file manipulation heartcrypt medusa obfuscation process-termination ransomware
Related entities
2 observables, 12 techniques (mitre), 3 malware

Description

The is a malicious tool used in conjunction with to disable anti-malware systems. It employs a -packed loader and a revoked certificate-signed to target and silence vendors. The imitates a legitimate CrowdStrike Falcon and uses techniques to hinder analysis. It provides various functionalities including , process and termination, and system disabling. The 's capabilities include removing callbacks, replacing functions, killing system threads, and detaching mini-filter devices. It uses unconventional methods like creating IRPs from scratch to perform file operations. The malware's sophisticated approach demonstrates the evolving tactics of cybercriminals in evading detection and disabling security measures.

External references