Summary:
Ransomware attacks have reached new the latest threat being the notorious Medusa ransomware. Medusa's distribution methods, behaviour, and impact, particularly on the country's health insurance program. Medusa, distributed as an executable file, infiltrates systems through exposed RDP servers, employing brute force attacks or phishing emails.[/subscribe_to_unlock_form]
Summary:
Ransomware attacks have reached new the latest threat being the notorious Medusa ransomware. Medusa's distribution methods, behaviour, and impact, particularly on the country's health insurance program. Medusa, distributed as an executable file, infiltrates systems through exposed RDP servers, employing brute force attacks or phishing emails.[emaillocker id="1283"]
Medusa encrypts files with the .MEDUSA extension, rendering them inaccessible, and leaves a ransom note instructing victims to contact the attackers via TOR chat or TOX ID. Notably, both communication channels are currently non-functional. The malware employs various evasion techniques, including packing with UPX and disguising itself as a Microsoft Word file to deceive users. The destructive actions of Medusa, such as encrypting files with AES-256 encryption, killing essential services and security software, and launching processes to delete backups and disk-related files crucial for recovery. Medusa goes further by deleting Volume Shadow Copy (VSS), making file recovery even more challenging.
That Medusa isn't limited to Windows systems, as a variant targets Linux servers, often deploying crypto-mining malware. They also provide insights into the MedusaLocker ransomware group's discovery in 2019, sharing information about their encrypted file extensions, targeted processes, and services disabled. As the analysis of Medusa continues, users are urged to stay informed about emerging threats and adopt proactive measures to safeguard their data and systems.
Threat Profile:

References:
Eventus Security Threat Research & Development Team
[/emaillocker]