Updated on 2022-10-05
CloudSEK researchers have a technical report out on the MedusaLocker ransomware, the same on which CISA also published a malware report back in June. Read more:
New U.S. federal warning highlights MedusaLocker group targeting health care organizations
The FBI and U.S. Cybersecurity and Infrastructure Security Agency warned of an uptick in activity from the MedusaLocker ransomware group. The group, which has been around since 2019, gained notoriety during the COVID-19 pandemic for targeting health care organizations. The group operates as a ransomware-as-a-service model, according to the joint alert, based on the way it splits payments. Medusa recently switched to a new infiltration method by targeting vulnerable RDP configurations. Then, it can carry out a variety of actions, including killing popular anti-virus software processes, schedules a task to run the ransomware every 15 minutes and deletes local backups.