#StopRansomware: Medusa Ransomware
ID: 730e60c1-5eb1-5a0a-94dc-9ffcc9d52c55
STIX ID: report--730e60c1-5eb1-5a0a-94dc-9ffcc9d52c55
Feed Name: CISA Cybersecurity Advisories
Threat Score
This joint advisory from FBI, CISA, and MS-ISAC documents the Medusa ransomware-as-a-service (RaaS) campaign active through February 2025, describing its affiliate model, double-extortion extortion and data leak site, common TTPs (PowerShell, certutil, PsExec, Rclone, RDP, Mimikatz), observed IOCs (file hashes, ransom notes, negotiation email addresses), and recommended mitigations (patching, MFA, network segmentation, backups, monitoring).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
