HomeSecurityMedusa Ransomware disables security tools with malicious driver

Medusa Ransomware disables security tools with malicious driver

The Medusa ransomware deploys a malicious driver program from a Chinese vendor and uses it to disable security tools running on infected systems, cybersecurity firm Elastic Security Labs.

See also: Medusa ransomware: Has targeted over 300 organizations in critical infrastructure

Medusa Ransomware driver

The driver, called smuol.sys, pretends to be a legitimate CrowdStrike Falcon. It is signed with a revoked certificate from a Chinese company and is protected using VMProtect.

Elastic, which named the driver AbyssWorker, has identified dozens of samples dating from August 2024 to February 2025, all signed, likely using stolen certificates.

The driver itself, as the cybersecurity firm points out, is not exclusive to the Medusa ransomware and has previously been observed being used under the name nbwdv.sys in social engineering attacks leading to backdoor infections.

See also: Medusa Ransomware has targeted over 40 organizations in 2025

The driver was signed with an expired certificate and, in order to ensure that it would work successfully, the attackers used a .bat to disable the Windows Time Service and set the system date to 2012. A binary control file was used to communicate with the driver.

Medusa Ransomware disables security tools with malicious driver

Elastic's analysis of AbyssWorker revealed that the driver installs a protection function during initialization, searching for and removing any handles to the client process in other processes.

Once installed and running, the Medusa Ransomware driver can execute requests for a wide range of functions, such as process manipulation, file editing, process intervention, API loading, hook removal, driver termination, and system reboot, allowing it to permanently terminate and disable security tools.

See also: Medusa ransomware group hits Victoria Racing Club

A malicious driver is a program or piece of software designed to exploit vulnerabilities in the system or computer, with the aim of performing malicious actions. Typically, these drivers are fake or tampered with and are installed on the computer without the user's knowledge or permission. Malicious drivers can be installed through infected files, email, or by exploiting vulnerabilities in the operating system. To avoid such threats, it is important to frequently update your operating system and drivers and use reliable security software.

Source: securityweek

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS