Medusa Attack Analysis
ID: 01a204e5-8063-50d7-b828-9a35f8135fb1
STIX ID: report--01a204e5-8063-50d7-b828-9a35f8135fb1
Feed Name: ReliaQuest Blog
ReliaQuest investigated a Medusa ransomware incident in June 2024 where attackers gained initial access via a compromised VPN account, conducted credential harvesting (NTDS and LSASS dumps), used RDP and management tools (AnyDesk, PDQDeploy) for lateral movement, installed a vulnerable kernel driver to unhook EDR, and deployed an encryptor across multiple hosts; the report catalogs IOCs, TTPs, and actionable mitigations (MFA, network segmentation, EDR/LSASS protections, backups and recovery playbooks).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
