Skip to Content

MedusaLocker ransomware

Updated on 2022-10-05

CloudSEK researchers have a technical report out on the MedusaLocker ransomware, the same on which CISA also published a malware report back in June. Read more:

  • Technical Analysis of MedusaLocker Ransomware
  • Alert (AA22-181A) #StopRansomware: MedusaLocker

New U.S. federal warning highlights MedusaLocker group targeting health care organizations

The FBI and U.S. Cybersecurity and Infrastructure Security Agency warned of an uptick in activity from the MedusaLocker ransomware group. The group, which has been around since 2019, gained notoriety during the COVID-19 pandemic for targeting health care organizations. The group operates as a ransomware-as-a-service model, according to the joint alert, based on the way it splits payments. Medusa recently switched to a new infiltration method by targeting vulnerable RDP configurations. Then, it can carry out a variety of actions, including killing popular anti-virus software processes, schedules a task to run the ransomware every 15 minutes and deletes local backups.

Read more

  • FBI and CISA warn: This ransomware is using RDP flaws to break into networks
  • Alert (AA22-181A) #StopRansomware: MedusaLocker