Researchers Hack Medusa Ransomware Group’s Cloud
ID: d6a5580e-b9a7-5906-9210-bc5d333e0541
STIX ID: report--d6a5580e-b9a7-5906-9210-bc5d333e0541
Feed Name: Cyber Press
Threat Score
- Researchers infiltrated a Medusa ransomware group's cloud storage and found rclone configuration and a put.io user token that allowed access to exfiltrated victim data (including Kansas City Area Transportation Authority files); they automated victim identification, recovered data, deleted sensitive files, and published detection guidance (a Sigma rule) to identify Put.io-related DNS queries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
