ABYSSWORKER is a malicious Windows kernel driver used primarily for defense evasion in ransomware intrusions. It is associated most prominently with Medusa operations and has also been observed in DragonForce activity and in commercially sold EDR-killer tooling such as AbyssKiller. The driver is commonly described as a custom-built, signed kernel component that masquerades as legitimate security software drivers, including Palo Alto Networks and CrowdStrike-related products, in order to blend into enterprise environments while operating with kernel privileges.
Its core purpose is to disable or degrade endpoint protection products before or during ransomware deployment. Reported functionality includes terminating protected security processes and threads, stripping or denying handles to protected malware client processes, removing or tampering with kernel notification callbacks, detaching mini-filters, replacing driver dispatch routines to break security tooling, restoring selected hooked kernel routines, performing file operations, and rebooting the system. These behaviors place it squarely in the class of kernel-level EDR killers and rootkit-like defensive bypass tools.
ABYSSWORKER has been used alongside bring-your-own-vulnerable-driver tradecraft and is frequently discussed in the same operational context as vulnerable process-killer drivers. In some campaigns it was installed by a loader packed with HeartCrypt, and multiple observed samples were signed with revoked or likely stolen certificates. Reporting also links the driver family to the earlier POORTRY designation, and some intrusion reporting uses Abyssworker and Poortry interchangeably.
The malware targets Windows systems and is intended for privileged execution as a kernel service on modern desktop and server environments. Its role in ransomware operations is typically pre-encryption or concurrent defense suppression, enabling operators to silence EDR and antivirus products, preserve access, and improve the reliability of subsequent payloads such as data theft tools, remote access implants, and ransomware encryptors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The drivers involved included Huawei’s HWAuidoOs2Ec.sys, Topaz Antifraud’s wsftprm.sys (CVE-2023-52271), Tower of Fantasy’s GameDriverx64.sys (CVE-2025-61155), and K7 Security’s K7RKScan.sys (CVE-2025-1055).
The drivers involved included Huawei’s HWAuidoOs2Ec.sys, Topaz Antifraud’s wsftprm.sys (CVE-2023-52271), Tower of Fantasy’s GameDriverx64.sys (CVE-2025-61155), and K7 Security’s K7RKScan.sys (CVE-2025-1055).
The drivers involved included Huawei’s HWAuidoOs2Ec.sys, Topaz Antifraud’s wsftprm.sys (CVE-2023-52271), Tower of Fantasy’s GameDriverx64.sys (CVE-2025-61155), and K7 Security’s K7RKScan.sys (CVE-2025-1055).
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Кроме того, в атаке фигурировал ABYSSWORKER — вредоносный драйвер, маскирующийся под продукт Palo Alto Networks.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
эксплуатировали уязвимые подписанные драйверы Huawei, Topaz Antifraud, Tower of Fantasy и K7 Security, чтобы получить привилегии уровня ядра | атакующие использовали в рамках подхода BYOVD (Bring Your Own Vulnerable Driver)... чтобы получить привилегии уровня ядра и завершить работу защитных решений
The binary is a 64-bit Windows PE driver named smuol.sys, and imitates a legitimate CrowdStrike Falcon driver.
These constant-returning functions are called repeatedly throughout the binary to hinder static analysis.
This ABYSSWORKER-related malicious kernel driver presents as Palo Alto Networks tdevflt.sys / Cortex XDR PnP Device Filter Driver.
28 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A custom signed driver used by Medusa operators in a BYOVD attack to disable endpoint detection and antivirus defenses prior to encryption.
A custom malicious driver used for defense evasion and impairment, specifically to terminate security processes as part of the intrusion.
Malicious driver used in the attack, disguised as a Palo Alto Networks product, as part of a BYOVD-style toolset to obtain kernel-level privileges and disable security solutions.
A custom-built malicious driver previously observed in Medusa ransomware attacks, referenced here as one of several drivers used in BYOVD-style activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.