National Cyber Warfare Foundation (NCWF)

Medusa Ransomware Uses Malicious Driver to Disable Anti-Malware with Stolen Certificates


0 user ratings
2025-03-21 13:33:04
milo
Blue Team (CND)
The threat actors behind the Medusa ransomware-as-a-service (RaaS) operation have been observed using a malicious driver dubbed ABYSSWORKER as part of a bring your own vulnerable driver (BYOVD) attack designed to disable anti-malware tools.
Elastic Security Labs said it observed a Medusa ransomware attack that delivered the encryptor by means of a loader packed using a packer-as-a-service (PaaS



Source: TheHackerNews
Source Link: https://thehackernews.com/2025/03/medusa-ransomware-uses-malicious-driver.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Blue Team (CND)



Copyright 2012 through 2025 - National Cyber Warfare Foundation - All rights reserved worldwide.