ABYSSWORKER
ABYSSWORKER is a malicious Windows kernel-mode driver/rootkit used for defense evasion, especially to disable or interfere with endpoint security products. It has been observed masquerading as legitimate security vendor drivers, including Palo Alto Networks Cortex XDR PnP Device Filter Driver (tdevflt.sys) and, in other reporting, a CrowdStrike Falcon driver. The malware is associated with BYOVD-style tradecraft and EDR-killer activity, and has been used alongside packed loaders such as HEARTCRYPT. Reporting links it to financially motivated ransomware operations including Medusa, DragonForce, and activity discussed in relation to Osiris intrusions; commercial tooling such as AbyssKiller pairs the ABYSSWORKER rootkit with a loader and has been observed in the wild. Some reporting also refers to related activity or samples as Poortry.
High-confidence capabilities described in the content include terminating processes and threads, removing or tampering with kernel callbacks, detaching MiniFilter components, replacing driver major functions to disable targeted drivers, restoring hooks, manipulating files, protecting the malware client process by stripping and denying handles, and rebooting the system. Elastic reported that ABYSSWORKER exposes multiple IOCTL handlers, requires a hardcoded enablement password, creates a device at \device\czx9umpTReqbOOKF and a symbolic link at \??\fqg0Et4KlNt4s1JT, and can target different EDR vendors. The malware has been signed with revoked or likely stolen certificates from Chinese companies; one reported sample masquerading as Palo Alto Networks tdevflt.sys had SHA256 8284c8676cc22c4b2e66826ac16986da7ddecba1f2776b16771be17bfdc45dc2 and was described as installable as a kernel service from C:\windows\temp\tdevflt.sys. Public reporting places ABYSSWORKER in ransomware intrusion chains as a kernel-level tool for silencing defenses prior to or during ransomware deployment.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Vulnerabilities exploited
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The drivers involved included Huawei’s HWAuidoOs2Ec.sys, Topaz Antifraud’s wsftprm.sys (CVE-2023-52271), Tower of Fantasy’s GameDriverx64.sys (CVE-2025-61155), and K7 Security’s K7RKScan.sys (CVE-2025-1055).
The drivers involved included Huawei’s HWAuidoOs2Ec.sys, Topaz Antifraud’s wsftprm.sys (CVE-2023-52271), Tower of Fantasy’s GameDriverx64.sys (CVE-2025-61155), and K7 Security’s K7RKScan.sys (CVE-2025-1055).
The drivers involved included Huawei’s HWAuidoOs2Ec.sys, Topaz Antifraud’s wsftprm.sys (CVE-2023-52271), Tower of Fantasy’s GameDriverx64.sys (CVE-2025-61155), and K7 Security’s K7RKScan.sys (CVE-2025-1055).
Groups observed using it
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Кроме того, в атаке фигурировал ABYSSWORKER — вредоносный драйвер, маскирующийся под продукт Palo Alto Networks.
Techniques & procedures
11 distinct techniques documented for this family, organized by ATT&CK tactic.
Privilege Escalation
1 technique
Privilege Escalation
эксплуатировали уязвимые подписанные драйверы Huawei, Topaz Antifraud, Tower of Fantasy и K7 Security, чтобы получить привилегии уровня ядра | атакующие использовали в рамках подхода BYOVD (Bring Your Own Vulnerable Driver)... чтобы получить привилегии уровня ядра и завершить работу защитных решений
Stealth
5 techniques
Stealth
The binary is a 64-bit Windows PE driver named smuol.sys, and imitates a legitimate CrowdStrike Falcon driver.
These constant-returning functions are called repeatedly throughout the binary to hinder static analysis.
This ABYSSWORKER-related malicious kernel driver presents as Palo Alto Networks tdevflt.sys / Cortex XDR PnP Device Filter Driver.
Defense Impairment
2 techniques
Defense Impairment
Impact
1 technique
Impact
IOCs tracked for this family
28 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Recent activity
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malicious driver used in the attack, disguised as a Palo Alto Networks product, as part of a BYOVD-style toolset to obtain kernel-level privileges and disable security solutions.
A custom-built malicious driver previously observed in Medusa ransomware attacks, referenced here as one of several drivers used in BYOVD-style activity.
ABYSSWORKER is referenced in connection with a malicious Windows kernel driver masquerading as Palo Alto Networks' tdevflt.sys. The driver is used for BYOVD-style defense evasion and process-killing tradecraft on Windows 10 and 11.
A custom malicious driver used in the intrusion to aid defense evasion, masquerading as a legitimate Palo Alto driver.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.