Medusa ransomware tallies hundreds of new victims, says updated advisory on group’s tactics

Medusa ransomware tallies hundreds of new victims, says updated advisory on group’s tactics
Medusa ransomware-as-a-service is expanding quickly by paying access brokers and exploiting newly disclosed software flaws, including Fortra GoAnywhere and BeyondTrust vulnerabilities. The U.S. government says the group has surpassed 500 victims and has frequently targeted the Healthcare and Public Health sector, while also reusing legitimate tools to evade detection. #Medusa #FortraGoAnywhere #BeyondTrust #Storm-1175

Keypoints

  • Medusa is hiring access brokers to gain entry into victim networks.
  • The group pays brokers from $100 to $1 million, with higher rewards for exclusivity.
  • Medusa quickly exploits newly announced vulnerabilities, often within 24 hours.
  • The Healthcare and Public Health sector remains a frequent target.
  • Medusa uses legitimate tools and living-off-the-land tactics to avoid detection.

Read More: https://cyberscoop.com/medusa-ransomware-tactics-cisa-advisory/