Campaigns
Medusa Ransomware Won't Stop

Medusa Ransomware Won't Stop

MedusaRansomwarewin.medusamedusalockerBATPowershell
Ransomware operation Medusa became operational in June 2021, according to Bleeping Computer. However, it gained significant momentum in 2023, targeting corporate victims worldwide with multimillion-dollar ransom demands. The ransomware gang has stepped up its effectiveness by launching a "Medusa Blog" in its recent rise. The platform serves to attract media attention by leaking data from victims who refuse to pay the ransom.

Indicators of Compromise

medusa-stealer.cc
anydeskupdates.com
winserverupdates.com
updateservicecenter.com
windowservicecemter.com
netviewremote.com
windowcsupdates.com
anydeskupdate.com
windowservicecenter.com
socket.af
ber6vjyb.com
study.abroad.ge
windowservicecentar.com
upd488.windowservicecemter.com
info.openjdklab.xyz
espet.se
medusacegu2ufmc3kx2kkqicrlcxdettsjcenhjena6uannk5f4ffuyd.onion
lockbitks2tvnmwk.onion
qd7pcafncosqfqu3ha6fcx4h6sr7tzwagzpcdcnytiw3b6varaeqv5yd.onion
gvlay6u4g53rxdi5.onion
svchost.com
lockbitapt6vx57t3eeqjofwgcglmutr3a35nygvokja5uuccip4ykyd.onion
www.securityondemand.com
lockbit-decryptor.com
orangebronze.com
jpz.nz
system.net.security
gvlay6y4g53rxdi5.onion
location.country
85.lp.ret.sbx.tg
iplo.ru

Campaign Guidance

Remediation, mitigation, notes, history and related intelligence

REMEDIATIONS
How to protect yourself from ransomware infections?

Double-check any suspicious emails, especially those sent from unknown addresses, and be wary of attachments or links they contain. Download software only from official pages and stores, and avoid opening downloads from shady pages, third-party downloaders, P2P networks, or clicking suspicious links.

Do not trust advertisements on dubious pages, and ensure that your operating system and installed programs are up-to-date. Regularly scanning your computer for threats and using reputable antivirus software can also help prevent and detect ransomware infections.

Reports & References2

Observed Countries29

AE (489)
AR (644)
BE (377)
BF (511)
BI (674)
BJ (126)
CA (564)
CI (846)
CN (287)
CY (394)
DE (987)
DJ (671)
ES (765)
FR (253)
GB (456)
GH (181)
GN (959)
IT (78)
KE (729)
MG (302)
ML (174)
NE (663)
NL (840)
RW (977)
SN (959)
TG (957)
TZ (434)
UG (265)
ZM (835)