Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to malware
MalwareRansomwareUsed by 1 actorExploits 3 CVEs

ABYSSWORKER

ABYSSWORKER is a malicious Windows kernel-mode driver/rootkit used for defense evasion, especially to disable or interfere with endpoint security products. It has been observed masquerading as legitimate security vendor drivers, including Palo Alto Networks Cortex XDR PnP Device Filter Driver (tdevflt.sys) and, in other reporting, a CrowdStrike Falcon driver. The malware is associated with BYOVD-style tradecraft and EDR-killer activity, and has been used alongside packed loaders such as HEARTCRYPT. Reporting links it to financially motivated ransomware operations including Medusa, DragonForce, and activity discussed in relation to Osiris intrusions; commercial tooling such as AbyssKiller pairs the ABYSSWORKER rootkit with a loader and has been observed in the wild. Some reporting also refers to related activity or samples as Poortry.

High-confidence capabilities described in the content include terminating processes and threads, removing or tampering with kernel callbacks, detaching MiniFilter components, replacing driver major functions to disable targeted drivers, restoring hooks, manipulating files, protecting the malware client process by stripping and denying handles, and rebooting the system. Elastic reported that ABYSSWORKER exposes multiple IOCTL handlers, requires a hardcoded enablement password, creates a device at \device\czx9umpTReqbOOKF and a symbolic link at \??\fqg0Et4KlNt4s1JT, and can target different EDR vendors. The malware has been signed with revoked or likely stolen certificates from Chinese companies; one reported sample masquerading as Palo Alto Networks tdevflt.sys had SHA256 8284c8676cc22c4b2e66826ac16986da7ddecba1f2776b16771be17bfdc45dc2 and was described as installable as a kernel service from C:\windows\temp\tdevflt.sys. Public reporting places ABYSSWORKER in ransomware intrusion chains as a kernel-level tool for silencing defenses prior to or during ransomware deployment.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

3 CVES
CVE-2025-1055Improper Authorization in K7 Security K7RKScan.sys IOCTL HandlerExploited in the wild

The drivers involved included Huawei’s HWAuidoOs2Ec.sys, Topaz Antifraud’s wsftprm.sys (CVE-2023-52271), Tower of Fantasy’s GameDriverx64.sys (CVE-2025-61155), and K7 Security’s K7RKScan.sys (CVE-2025-1055).

via help net securityhelpnetsecurity.com
CVE-2023-52271Arbitrary PPL Process Termination in Topaz Antifraud wsftprm.sysExploited in the wild

The drivers involved included Huawei’s HWAuidoOs2Ec.sys, Topaz Antifraud’s wsftprm.sys (CVE-2023-52271), Tower of Fantasy’s GameDriverx64.sys (CVE-2025-61155), and K7 Security’s K7RKScan.sys (CVE-2025-1055).

via help net securityhelpnetsecurity.com
CVE-2025-61155Arbitrary Process Termination in Tower of Fantasy GameDriverX64.sysExploited in the wild

The drivers involved included Huawei’s HWAuidoOs2Ec.sys, Topaz Antifraud’s wsftprm.sys (CVE-2023-52271), Tower of Fantasy’s GameDriverx64.sys (CVE-2025-61155), and K7 Security’s K7RKScan.sys (CVE-2025-1055).

via help net securityhelpnetsecurity.com
THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
DragonForce

Кроме того, в атаке фигурировал ABYSSWORKER — вредоносный драйвер, маскирующийся под продукт Palo Alto Networks.

via xakepxakep.ru
MITRE ATT&CK

Techniques & procedures

11 distinct techniques documented for this family, organized by ATT&CK tactic.

Privilege Escalation

1 technique
T1068Exploitation for Privilege EscalationEvidence7

эксплуатировали уязвимые подписанные драйверы Huawei, Topaz Antifraud, Tower of Fantasy и K7 Security, чтобы получить привилегии уровня ядра | атакующие использовали в рамках подхода BYOVD (Bring Your Own Vulnerable Driver)... чтобы получить привилегии уровня ядра и завершить работу защитных решений

Stealth

5 techniques
T1014RootkitEvidence1

The binary is a 64-bit Windows PE driver named smuol.sys, and imitates a legitimate CrowdStrike Falcon driver.

T1027Obfuscated Files or InformationEvidence1

These constant-returning functions are called repeatedly throughout the binary to hinder static analysis.

T1036MasqueradingEvidence1

This ABYSSWORKER-related malicious kernel driver presents as Palo Alto Networks tdevflt.sys / Cortex XDR PnP Device Filter Driver.

T1070Indicator RemovalEvidence1

Additionally, it removes callbacks registered through a MiniFilter driver and, optionally, removes devices belonging to a specific module.

T1070.004File DeletionEvidence1

чтобы получить привилегии уровня ядра и завершить работу защитных решений

Defense Impairment

2 techniques
T1222File and Directory Permissions ModificationEvidence1

The deletion handler sets the file attribute to ATTRIBUTE_NORMAL to unprotect any read-only file and sets the file disposition to delete (disposition_info.DeleteFile = 1) to remove the file using the IRP_MJ_SET_INFORMATION IRP.

T1553.002Code SigningEvidence1

All samples are signed using likely stolen, revoked certificates from Chinese companies.

Impact

1 technique
T1489Service StopEvidence1

With these two handlers you can terminate any process or a thread by their PID or Thread ID (TID) using PsTerminateProcess and PsTerminateThread.

Other

2 techniques
T1562Impair DefensesEvidence4

Malicious kernel driver used with BYOVD-style defense evasion tradecraft.

T1562.001Disable or Modify ToolsEvidence2

Cybercriminals are increasingly bringing their own drivers — either exploiting a vulnerable legitimate driver or using a custom-built driver to disable endpoint detection and response (EDR) systems and evade detection or prevention capabilities.

INDICATORS OF COMPROMISE

IOCs tracked for this family

28 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
3 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
25 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in app11 days ago
domain●●●●●●●●●●●●View more in app11 days ago
hash.sha1●●●●●●●●●●●●View more in app11 days ago
hash.sha1●●●●●●●●●●●●View more in app11 days ago
hash.sha256●●●●●●●●●●●●View more in app11 days ago
hash.sha256●●●●●●●●●●●●View more in app11 days ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching28

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities3

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping11

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.