CISA, FBI and MS-ISAC Alert on Medusa Ransomware
ID: 4a7ee500-2e77-5d61-8451-58e68943b7f0
STIX ID: report--4a7ee500-2e77-5d61-8451-58e68943b7f0
Feed Name: Halcyon Blog
CISA, the FBI, and MS-ISAC warned about the Medusa ransomware group which has targeted over 300 victims across critical infrastructure sectors using a double-extortion model; the report details their use of phishing, exploitation of a Fortinet FortiClient EMS vulnerability (CVE-2023-48788), RDP brute-force, credential theft (Mimikatz), lateral movement tools (PsExec, RDP, AnyDesk, ConnectWise), and destructive behaviors like terminating services, deleting Volume Shadow Copies, and encrypting files with AES-256 and RSA to maximize operational disruption and extortion pressure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
