Medusa ransomware tallies hundreds of new victims, says updated advisory on group’s tactics
ID: 0f6ebf57-86e5-52f9-bea9-80f4b61d5ca3
STIX ID: report--0f6ebf57-86e5-52f9-bea9-80f4b61d5ca3
Feed Name: CyberScoop
The article summarizes an updated U.S. government advisory on the Medusa ransomware-as-a-service group, reporting that the gang leverages access brokers (paid $100–$1,000,000), rapidly weaponizes newly announced exploits (often within 24 hours), exploits vulnerabilities such as GoAnywhere and BeyondTrust, uses living-off-the-land and legitimate remote management tools for lateral movement and exfiltration, and has expanded its victim count from roughly 300 to more than 500 with frequent impacts to the healthcare sector.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
