logo

New Medusa Botnet Targets Linux Users Via Mirai

ID: cd27591c-9cd7-578c-ad2a-f4bd6335124e

STIX ID: report--cd27591c-9cd7-578c-ad2a-f4bd6335124e

Feed Name: Cyble Blog

Threat Score
72/100

Date Published: 2024-10-29

Date Updated: 2026-07-17

...
...

**Executive Summary:** This report analyzes a Mirai-borne payload (Medusa) observed in Jan-2023 that infects Linux-based routers/IoT devices and implements multi-functional malicious behavior — layered DDoS (including IP spoofing), ransomware that encrypts files and attempts destructive cleanup, Telnet brute-force with payload injection, SSH/backdoor capabilities, and system information exfiltration to a medusa-stealer.cc C2; the document provides code excerpts, MITRE ATT&CK mappings, recommended mitigations, and a set of IOCs (hashes, URLs, C2 IP).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.