Medusa Ransomware Surges As FBI Share Insight
ID: fb9de3e4-c872-5e4f-ba05-9a04d1398e15
STIX ID: report--fb9de3e4-c872-5e4f-ba05-9a04d1398e15
Feed Name: Cyble Blog
**Executive Summary:** The FBI and CISA advisory, corroborated by Cyble data, describes a sharp increase in Medusa RaaS activity in early 2025 (60 victims in the first 72 days; 414 total recorded attacks), with frequent targeting of critical infrastructure sectors; the report documents TTPs including phishing, exploitation of known CVEs (e.g., CVE-2024-1709, CVE-2023-48788), living-off-the-land and legitimate remote management tools, common scanned ports and remote access methods, and provides IoCs (ransom note filename and two file hashes), concluding with prioritized defensive measures such as patching, phishing training, segmentation, and ransomware-resistant backups.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
