Medusa ransomware gang has hit over 500 organizations, CISA warns
ID: 46346e74-806c-5161-ade7-0dda3f6a6bb5
STIX ID: report--46346e74-806c-5161-ade7-0dda3f6a6bb5
Feed Name: Help Net Security
Threat Score
US agencies warn that Medusa ransomware — operating as a Ransomware-as-a-Service with affiliates — has impacted over 500 organizations across healthcare, defense, manufacturing, government, IT, and financial sectors; actors rapidly exploit public vulnerabilities (within 24 hours), use common tools (PowerShell, Mimikatz, AnyDesk, SimpleHelp) and an encryptor (gaze.exe) that appends .medusa, and conduct double-extortion by publishing stolen data and pressuring victims to pay.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
