logo

MEDUSA RANSOMWARE EXPOSED BY RANSOMEDVC

ID: 7cf2a1f5-7af4-5c20-b6fb-6f389dea1a79

STIX ID: report--7cf2a1f5-7af4-5c20-b6fb-6f389dea1a79

Feed Name: THE RAVEN FILE

Threat Score
70/100

Date Published: 2025-07-10

Date Updated: 2026-04-19

Author: RakeshKrish

...
...

Executive summary: A RansomedVC leak released Medusa ransomware group chat transcripts (Dec 2022–Mar 2023) that reveal affiliate names, an initial-access broker (drumrlu), exploitation of CVE-2022-26134 and other RCEs, tooling (Volatility, GMER), persistence attempts (a Safe Mode service script), targeting patterns (US/Brazil, Fortinet access), and the group's use of a DLS to publish victim data—providing actionable operational details for detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.