Research coverage · Availability not listed

Abyssos v2.1F

This record covers one publicly reported 64-bit Windows sample. Proofmetry reached 25 intended paths in a fixed research matrix, but current customer availability for Abyssos is not publicly listed.

Research and product are different scopes: the 25 research scenarios are not 25 product-supported workflows.

Record metadata

Analyzed variant and availability

Evidence vocabulary

Proofmetry Evidence Status

The 23 corroborated outcomes combine different evidence levels. They must not be restated as 23 endpoint effects.

  1. 01

    Mapped

    A behavior or handler was identified through analysis.

  2. 02

    Path reached

    Execution entered the intended code path.

  3. 03

    Result observed

    A meaningful intermediate or returned result was observed.

  4. 04

    Terminal state observed

    The workflow reached a defined completion or stop condition.

  5. 05

    Endpoint effect confirmed

    The intended native endpoint or network effect was corroborated.

Research evidence

Evidence matrix

The matrix preserves the difference between task delivery, path reach, returned result, terminal state, and endpoint effect.

Evidence status and claim boundaries for the analyzed Abyssos v2.1F sample
Research itemPublic evidenceClaim boundary
Fixed scenario matrixPath reached: all 25 intended paths were reached through the native v2.1F client.Research scenarios are not identical to current product workflows.
Corroborated outcomesResult, terminal state, or endpoint effect: 23 scenarios produced at least one of these evidence forms.The public aggregate does not state that all 23 reached endpoint-effect confirmation.
Remote-desktop qualityPath reached: the task arrived in the intended sequence.A perceptual image-quality change was not independently measured and is not claimed.
Hidden-desktop inputPath reached / terminal state observed: input reached dispatch and orderly teardown.Cursor movement was not independently observed and is not claimed.
Lifecycle stopsTerminal state observed: some stops ended a worker without an ordinary command result.Absence of an ordinary result does not erase the terminal-state evidence.
DisconnectTerminal state observed: the process ended and the session reset.A completed network exchange alone would not establish that endpoint outcome.
Additional static pathsMapped: power control, elevation, injection, recovery, module loading, and arbitrary file, URL, or payload execution were identified.They were not executed in this research and are not presented as observed behavior.

Behavior categories

What the research exercised

The original Abyssos v2.1F client produced the observed behavior in the isolated environment.

Host and process inventory

One long-lived process produced host inventory with recurring process and connection-owner inventories.

File and collection activity

The sample returned file contents, wrote C2-supplied bytes, copied and deleted files, and built memory-only and on-disk archives.

Shell and process control

The exercised paths included shell activity, socket-owner inventory, and a related process termination action keyed by PID.

Desktop activity

Desktop creation, capture, image encoding, input dispatch, and lifecycle behavior were exercised, with two effect-specific claims withheld.

Lifecycle behavior

Worker stops and process disconnect produced distinct result and terminal-state patterns.

Environment-sensitive initialization

The sample file remained unmodified, but a standard Windows cryptography module had to be loaded into the process before native transport initialized.

Availability boundary: These are researched categories, not a published product test catalog. Abyssos customer availability is not currently listed.

Known limitations

Keep conclusions pinned to v2.1F.

  • The findings apply to one Abyssos v2.1F sample and the paths mapped or exercised in this research.
  • Zscaler’s detailed technical narrative examines v2.4F; Proofmetry’s version-specific findings come from independent analysis of the listed v2.1F binary.
  • Research scenarios are not identical to current product workflows, and current Abyssos availability is not publicly confirmed.
  • A perceptual image-quality change and hidden-desktop cursor movement were not independently observed; neither effect is claimed.
  • Additional statically identified paths were not executed and are not presented as observed behavior.
  • Initialization was environment-sensitive in the tested process, so an initial run without network activity could understate capability.
  • Detection and dataset outcomes depend on the customer’s sensors, configuration, collection design, and evidence.

Revision history

Coverage record changes

Abyssos v2.1F public coverage record revision history
DateRecordChange
August 30, 2026Website coverage record 1.0Initial public coverage record separating Research Brief 002, revision 1.1, from unlisted product availability. This record number is not a Threat Pack version.

Research coverage

Discuss whether Abyssos fits your detection or data objective.

Current preview availability is not publicly listed. We can confirm variant and behavior-test fit during the demo process.

Get a demo