CISA: More than 300 critical infrastructure orgs attacked by Medusa ransomware
ID: 844310a6-763f-5dba-92ed-2655f0a2d182
STIX ID: report--844310a6-763f-5dba-92ed-2655f0a2d182
Feed Name: The Record from Recorded Future News
The Medusa ransomware gang, operating as a ransomware-as-a-service (RaaS), has attacked over 300 victims across critical infrastructure and multiple industries using phishing and exploitation of unpatched vulnerabilities (including CVE-2024-1709 and CVE-2023-48788). U.S. agencies warn affiliates and initial access brokers help obtain access while developers control ransom negotiations; the group runs a leak site, practices aggressive extortion (including reports of potential triple extortion), and has affected schools, municipalities, government agencies, and private sector organizations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
