Medusa ransomware affiliate tried triple extortion scam – up from the usual double demand
ID: bc0f13a8-b8fa-51bc-b8b7-1fc51209b9cb
STIX ID: report--bc0f13a8-b8fa-51bc-b8b7-1fc51209b9cb
Feed Name: The Register (Security)
The joint FBI/CISA/MS-ISAC advisory highlights Medusa as a global ransomware-as-a-service operation that uses affiliates to gain access (often via credential phishing and exploited CVEs such as CVE-2024-1709 and CVE-2023-48788), performs data exfiltration and encryption with living-off-the-land tools (AnyDesk, ConnectWise, RDP, PsExec) plus Mimikatz and Rclone, and employs double extortion — with at least one observed case of a demand for an additional payment (triple extortion); Medusa has claimed 300+ victims across critical sectors and demands ransoms ranging into the millions, and the advisory recommends backups, network segmentation, MFA, timely patching, and other defenses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
