Cyber Security News

Medusa Ransomware Hacked 300+ Organizations Worldwide from Variety of Critical Infrastructure

A highly sophisticated ransomware variant named Medusa has compromised over 300 organizations worldwide from critical infrastructure sectors.

The attacks have targeted a wide array of industries including medical, education, legal, insurance, technology, and manufacturing sectors, demonstrating the threat actor’s broad operational focus and capabilities.

The Medusa ransomware variant, first identified in June 2021, operates as a ransomware-as-a-service (RaaS) model where developers recruit affiliates through cybercriminal forums, offering potential payments between $100 USD and $1 million USD for successful breaches.

While the operation has evolved to include more affiliates, core operations such as ransom negotiation remain centrally controlled by the developers.

Analysts at CISA identified that Medusa actors employ sophisticated tactics to maintain persistence within victim networks, including the creation of domain accounts to preserve access to compromised systems.

The investigation revealed that threat actors typically leverage initial access brokers (IABs) to gain entry into targeted networks through phishing campaigns and exploitation of unpatched vulnerabilities.

The ransomware operation employs a double extortion model, where victims must pay not only to decrypt files but also to prevent exfiltrated data from being published.

In a particularly concerning development, FBI investigations uncovered instances where victims who paid the initial ransom were subsequently contacted by different Medusa actors claiming the first negotiator had stolen the payment, demanding an additional half of the original sum to provide the “true decryptor”—potentially indicating a triple extortion scheme.

Once inside networks, Medusa actors utilize living off the land techniques and legitimate system tools to avoid detection while conducting reconnaissance.

They scan for specific ports including FTP (21), SSH (22), HTTP (80), SQL databases (1433), and Remote Desktop Protocol (3389) to identify valuable assets within the network.

Operations and Methods

The technical sophistication of Medusa is evident in the obfuscation techniques employed during attacks.

Actors have been observed using increasingly complex PowerShell commands to evade detection. In one example documented in the advisory, threat actors use base64 encrypted commands with specific execution settings: “powershell -exec bypass -enc “.

In more advanced cases, they employ multi-layered obfuscation where payloads are compressed with gzip, decompressed in memory, and executed through scriptblocks.

For lateral movement, Medusa actors deploy a variety of legitimate remote access software including AnyDesk, ConnectWise, and Splashtop, alongside malicious use of PsExec to execute commands across compromised networks.

The ransomware component, identified as “gaze.exe,” terminates all services related to backups, security, databases, and communication before deleting shadow copies and encrypting files with AES-256 encryption.

Encrypted files receive a distinctive “.medusa” file extension, and ransom notes direct victims to make contact via Tor browser-based live chat or the encrypted Tox messaging platform.

The federal advisory includes specific mitigations for organizations, emphasizing network segmentation, implementation of multi-factor authentication, regular patching of vulnerabilities, and maintenance of offline backups to minimize the impact of potential Medusa ransomware attacks.

Are you from SOC/DFIR Teams? – Analyse Malware Incidents & get live Access with ANY.RUN -> Start Now for Free.

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago