MEDUSA RANSOMWARE: SETTING STRONG FOOTHOLD
ID: 46f1a877-8e6d-5cce-acdc-a5cfd02a8fe3
STIX ID: report--46f1a877-8e6d-5cce-acdc-a5cfd02a8fe3
Feed Name: THE RAVEN FILE
Threat Score
This report analyzes the Medusa ransomware group (distinct from MedusaLocker), covering its victimology (hundreds of victims, heavy US/English-speaking targeting), infection cycle and exploited CVEs, ransomware internals and post-compromise actions, darkweb data-leak site and TOR infrastructure, partnerships for leak dissemination, and a set of IOCs (MD5s, IPs, onion domains, emails) to support detection and hunting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
