Elastic Security Labs analyzed ABYSSWORKER, a malicious 64-bit Windows kernel driver deployed in financially motivated MEDUSA ransomware activity to disable or evade endpoint detection and response protections. The driver was delivered with a loader packed by HEARTCRYPT and masqueraded as a CrowdStrike Falcon driver; samples were signed using likely stolen certificates associated with Chinese companies that have since been revoked.
ABYSSWORKER provides extensive kernel-level anti-EDR capabilities, including removing security callbacks, hijacking targeted driver dispatch routines, detaching minifilter devices, and terminating processes and system threads. It can also restore NTFS and PNP dispatch functions and perform file operations, while protecting its malware client from external handle access. Elastic observed samples from August 2024 through February 2025 and released YARA coverage and sample hashes to support detection.

Get the actors, campaigns, and ATT&CK mapping behind it.
5 events from the most recent confirmed update back to the earliest known activity.
Elastic found approximately a dozen ABYSSWORKER samples on VirusTotal, with the identified first-seen date range extending through February 24, 2025.
A second ABYSSWORKER reference sample with SHA-256 b7703a59c39a0d2f7ef6422945aaeaaf061431af0533557246397551b8eed505 was first seen on VirusTotal.
A reference ABYSSWORKER sample with SHA-256 6a2a0f9c56ee9bf7b62e1d4e1929d13046cd78a93d8c607fe4728cc5b1e8d050 was first seen on VirusTotal.
Elastic identified ABYSSWORKER samples with VirusTotal first-seen dates beginning on August 8, 2024.
Google Cloud Mandiant publicly disclosed the malicious POORTRY driver, which Elastic assesses as the earliest public mention of the ABYSSWORKER driver family.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.