New Medusa Botnet Targets Linux Users Via Mirai
ID: cd27591c-9cd7-578c-ad2a-f4bd6335124e
STIX ID: report--cd27591c-9cd7-578c-ad2a-f4bd6335124e
Feed Name: Cyble Blog
**Executive Summary:** This report analyzes a Mirai-borne payload (Medusa) observed in Jan-2023 that infects Linux-based routers/IoT devices and implements multi-functional malicious behavior — layered DDoS (including IP spoofing), ransomware that encrypts files and attempts destructive cleanup, Telnet brute-force with payload injection, SSH/backdoor capabilities, and system information exfiltration to a medusa-stealer.cc C2; the document provides code excerpts, MITRE ATT&CK mappings, recommended mitigations, and a set of IOCs (hashes, URLs, C2 IP).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
