Close Menu
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
What's Hot

Dyson V16 Piston Animal first impressions: The best new Dyson vacuum cleaner is surprisingly under $1,000. Is it worth it?

Looking for guilt-free screen time for your kids? This $45 app can help

Katei, Le Seseraphim, and Illit release “Iconic by Mistake” music video

Facebook X (Twitter) Instagram
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
Facebook X (Twitter) Instagram
FYMOUS News
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
FYMOUS News
Home » Medusa ransomware uses malicious drivers to disable malware with stolen certificates
Celebrities

Medusa ransomware uses malicious drivers to disable malware with stolen certificates

By March 21, 2025No Comments4 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

March 21, 2025Ravi LakshmananRansomware / BYOVD

The threat actors behind Medusa Ransomware Asai Assen Service (RAAS) operations have been observed using a malicious driver called Abyssworker as part of Bring’s own Vulnerable Driver (BYOVD) attack, designed to disable anti-malware tools.

Elastic Security Labs said it had observed a Medusa ransomware attack that provides cryptocurrencies using a loader packed using a Packer-as-a-Service (PAAS) called HeartCrypt.

“The loader was deployed along with a driver signed with a certificate revoked from a Chinese vendor named Abyssworker, which we will install on the victim machine and use to target and silence various EDR vendors,” the company said in its report.

The driver in question, “Smuol.sys” mimics the falcon driver (“csagent.sys”) of legitimate crowd interruption. Dozens of Abyselker artifacts were detected on the Wilstotal platform from August 8, 2024 to February 25, 2025. All identified samples were signed using stolen and revoked certificates from Chinese companies.

Cybersecurity

The fact that it is signed to malware gives you a veneer of trust, allowing you to bypass your security system without attracting attention. It is worth noting that the Endpoint Detection and Response (EDR) Killing Driver was previously documented in January 2025 by ConnectWise under the name “NBWDV.SYS”.

Upon initialization and launching, AbysSworker is designed to add the process ID to the list of global protection processes, listen for incoming device I/O control requests, and is sent to the appropriate handler based on the I/O control code.

“These handlers cover a wide range of operations, from file manipulation to process and driver termination, providing a comprehensive set of tools that can be used to terminate or permanently disable the EDR system,” Elastic said.

A partial list of I/O control codes can be found below –

0x222080 – enable driver by sending password “7n6bcaoecbitsur5 -h4rp2nkqxybfkb0f -wgbjghgh20pwuun1 -zxfxdioyps6htp0x” 0x2220c0 -Required kernel Apis 0x2222184 -Copy 0x22180 -ded ded 0x2222408 – Kill system thread with module name 0x222400 – Remove notification callback with module name 0x2220C0 – Load API – Process ID 0x2222140 – End process 0x222140 – Thread ID 0x222084 – Disabled malware 0x2264 – Machine

Of particular interest is 0x222400. This can be used to blind security products by searching and deleting all registered notification callbacks. This is an approach that has also been adopted by other EDR kill input tools such as EDRSandblast and RealBlindingEdr.

The findings follow a report on how threat actors are threatening legal but interferable kernel drivers related to Check Point’s ZoneAlarm Antivirus software.

Privileged access was then abused by threat access, establishing Remote Desktop Protocol (RDP) connections to infected systems, encouraging persistent access. The loophole is then inserted through a checkpoint.

“VSDATANT.SYS operates with high levels of kernel privileges, allowing attackers to take advantage of the vulnerability, bypassing security protections and antivirus software, and gain full control of the infected machine,” the company said.

Cybersecurity

“When these defenses were bypassed, the attacker had full access to the underlying system, and the attacker had access to sensitive information, such as the user’s passwords and other stored credentials. This data was expanded and opened the door for further exploitation.”

This development is due to the use of ransom hub (aka green bottle and cyclops) ransomware operations due to the use of codename betruger, codenamed multifunctional backnames that have not been previously documented by at least one affiliate.

Implants come with features that are normally associated with malware deployed as precursors of ransomware, such as screenshots, keylogs, network scans, privilege escalations, qualification investments, and data exfiltration to remote servers.

“The Betruger feature indicates that it may have been developed to minimize the number of new tools dropped on the target network while a ransomware attack was being prepared,” said Symantec, owned by Broadcom, as a sort of deviation from other custom tools developed for data delamination from other custom tools developed by the Ransomware Group.

“Using custom malware other than encrypting payloads is relatively uncommon in ransomware attacks. Most attackers rely on legal tools, living off the land and rely on public malware such as Mimikatz and Cobalt Strike.”

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleWhy is Trump dismantling the Department of Education? And what’s next? | Court News
Next Article UAT-5918 Targeting critical infrastructure in Taiwan using webshells and open source tools

Related Posts

Amy Adams wears a little black dress on ‘Late Night’

June 10, 2026

Queen Camilla adorns Fiona Claire’s feathers for London outing

June 10, 2026

Taylor Swift’s beauty at the ‘Toy Story 5’ premiere

June 10, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Dyson V16 Piston Animal first impressions: The best new Dyson vacuum cleaner is surprisingly under $1,000. Is it worth it?

Looking for guilt-free screen time for your kids? This $45 app can help

Katei, Le Seseraphim, and Illit release “Iconic by Mistake” music video

III Points 2026 adds GZA, Bone Thugs-N-Harmony, Flying Lotus, and more

Trending Posts

Katei, Le Seseraphim, and Illit release “Iconic by Mistake” music video

June 10, 2026

III Points 2026 adds GZA, Bone Thugs-N-Harmony, Flying Lotus, and more

June 10, 2026

Megan Thee Stallion, David Guetta and EJAE share FIFA World Cup song ‘DNA’

June 10, 2026

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to The FYMOUS, a modern digital media platform dedicated to celebrities, artists, influencers, brands, entertainment culture, and the growing TwinH ecosystem.

We bring audiences closer to the people, stories, trends, and collaborations shaping today’s culture. From exclusive celebrity news and music releases to influencer highlights, brand partnerships, and TwinH activations, The FYMOUS delivers engaging content designed for the next generation of digital audiences.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.