The Medusa ransomware deploys a malicious driver program from a Chinese vendor and uses it to disable security tools running on infected systems, cybersecurity firm Elastic Security Labs.
See also: Medusa ransomware: Has targeted over 300 organizations in critical infrastructure

The driver, called smuol.sys, pretends to be a legitimate CrowdStrike Falcon. It is signed with a revoked certificate from a Chinese company and is protected using VMProtect.
Elastic, which named the driver AbyssWorker, has identified dozens of samples dating from August 2024 to February 2025, all signed, likely using stolen certificates.
The driver itself, as the cybersecurity firm points out, is not exclusive to the Medusa ransomware and has previously been observed being used under the name nbwdv.sys in social engineering attacks leading to backdoor infections.
See also: Medusa Ransomware has targeted over 40 organizations in 2025
The driver was signed with an expired certificate and, in order to ensure that it would work successfully, the attackers used a .bat to disable the Windows Time Service and set the system date to 2012. A binary control file was used to communicate with the driver.

Elastic's analysis of AbyssWorker revealed that the driver installs a protection function during initialization, searching for and removing any handles to the client process in other processes.
Once installed and running, the Medusa Ransomware driver can execute requests for a wide range of functions, such as process manipulation, file editing, process intervention, API loading, hook removal, driver termination, and system reboot, allowing it to permanently terminate and disable security tools.
See also: Medusa ransomware group hits Victoria Racing Club
A malicious driver is a program or piece of software designed to exploit vulnerabilities in the system or computer, with the aim of performing malicious actions. Typically, these drivers are fake or tampered with and are installed on the computer without the user's knowledge or permission. Malicious drivers can be installed through infected files, email, or by exploiting vulnerabilities in the operating system. To avoid such threats, it is important to frequently update your operating system and drivers and use reliable security software.
Source: securityweek
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
