cognitive cybersecurity intelligence

News and Analysis

Search

Medusa ransomware deployed via malicious Windows driver

Researchers from Elastic Security Labs have discovered a ransomware campaign that uses a malicious, expired Windows driver from Chinese vendor AbyssWorker. The driver evades security controls by passing certificate checks using system date manipulation, disabling security tools and executing harmful operations on infected systems. This highlights the increasing sophistication of ransomware attacks and the importance of implementing in-depth defense strategies that transcend conventional endpoint protections.

Source: www.scmagazine.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts