ABYSSWORKER is a malicious 64-bit Windows kernel driver, also tracked as POORTRY, designed principally as an EDR killer and kernel-mode rootkit. It has been used in financially motivated ransomware intrusions, including operations involving Medusa, DragonForce, and Osiris, and is distributed commercially in combination with a HeartCrypt-packed loader as AbyssKiller. Samples have masqueraded as legitimate endpoint-security drivers and have used stolen or otherwise abused code-signing certificates.
The driver provides broad defense-evasion capabilities through an IOCTL-controlled interface. It can terminate processes and threads; remove process, image-load, thread, object-manager, registry, and minifilter callbacks; detach minifilter devices; and replace a target driver’s dispatch routines to disable it. ABYSSWORKER can also restore selected kernel driver dispatch functions if they have been hooked, manipulate files through direct I/O request construction, and reboot the host. A client-protection function strips existing handles to its controlling process and blocks new process or thread handles, impeding security tooling and incident-response activity. Its use enables ransomware operators to suppress endpoint protections before subsequent payload deployment.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The drivers involved included Huawei’s HWAuidoOs2Ec.sys, Topaz Antifraud’s wsftprm.sys (CVE-2023-52271), Tower of Fantasy’s GameDriverx64.sys (CVE-2025-61155), and K7 Security’s K7RKScan.sys (CVE-2025-1055).
The drivers involved included Huawei’s HWAuidoOs2Ec.sys, Topaz Antifraud’s wsftprm.sys (CVE-2023-52271), Tower of Fantasy’s GameDriverx64.sys (CVE-2025-61155), and K7 Security’s K7RKScan.sys (CVE-2025-1055).
The drivers involved included Huawei’s HWAuidoOs2Ec.sys, Topaz Antifraud’s wsftprm.sys (CVE-2023-52271), Tower of Fantasy’s GameDriverx64.sys (CVE-2025-61155), and K7 Security’s K7RKScan.sys (CVE-2025-1055).
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Кроме того, в атаке фигурировал ABYSSWORKER — вредоносный драйвер, маскирующийся под продукт Palo Alto Networks.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
эксплуатировали уязвимые подписанные драйверы Huawei, Topaz Antifraud, Tower of Fantasy и K7 Security, чтобы получить привилегии уровня ядра | атакующие использовали в рамках подхода BYOVD (Bring Your Own Vulnerable Driver)... чтобы получить привилегии уровня ядра и завершить работу защитных решений
Cybercriminals are "using a custom-built driver to disable endpoint detection and response (EDR) systems"; ABYSSWORKER is a 64-bit Windows PE driver that installs on the victim machine.
"Most were VMProtect packed" and ABYSSWORKER repeatedly invokes constant-returning functions based on opaque predicates and derivation functions "to hinder static analysis."
This ABYSSWORKER-related malicious kernel driver presents as Palo Alto Networks tdevflt.sys / Cortex XDR PnP Device Filter Driver.
28 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A custom signed driver used by Medusa operators in a BYOVD attack to disable endpoint detection and antivirus defenses prior to encryption.
A custom malicious driver used for defense evasion and impairment, specifically to terminate security processes as part of the intrusion.
Malicious driver used in the attack, disguised as a Palo Alto Networks product, as part of a BYOVD-style toolset to obtain kernel-level privileges and disable security solutions.
A custom-built malicious driver previously observed in Medusa ransomware attacks, referenced here as one of several drivers used in BYOVD-style activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.