logo

Researchers Hack Medusa Ransomware Group’s Cloud

ID: d6a5580e-b9a7-5906-9210-bc5d333e0541

STIX ID: report--d6a5580e-b9a7-5906-9210-bc5d333e0541

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2024-07-29

Date Updated: 2026-04-13

Author: Kaaviya

...
...

- Researchers infiltrated a Medusa ransomware group's cloud storage and found rclone configuration and a put.io user token that allowed access to exfiltrated victim data (including Kansas City Area Transportation Authority files); they automated victim identification, recovered data, deleted sensitive files, and published detection guidance (a Sigma rule) to identify Put.io-related DNS queries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.