MEDUSA RANSOMWARE EXPOSED BY RANSOMEDVC
ID: 7cf2a1f5-7af4-5c20-b6fb-6f389dea1a79
STIX ID: report--7cf2a1f5-7af4-5c20-b6fb-6f389dea1a79
Feed Name: THE RAVEN FILE
Threat Score
Executive summary: A RansomedVC leak released Medusa ransomware group chat transcripts (Dec 2022–Mar 2023) that reveal affiliate names, an initial-access broker (drumrlu), exploitation of CVE-2022-26134 and other RCEs, tooling (Volatility, GMER), persistence attempts (a Safe Mode service script), targeting patterns (US/Brazil, Fortinet access), and the group's use of a DLS to publish victim data—providing actionable operational details for detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
