Medusa ransomware uses malicious Windows driver ABYSSWORKER to disable security tools

Medusa ransomware uses malicious Windows driver ABYSSWORKER to disable security tools, making detection and mitigation more difficult.

Security Affairs
Shedding light on the ABYSSWORKER driver — Elastic Security Labs

Elastic Security Labs describes ABYSSWORKER, a malicious driver used with the MEDUSA ransomware attack-chain to disable anti-malware tools.