Skip to main content

Tag: medusa ransomware

7 articles

Hospital corridor with staff, medical device, and laptop, well-lit with daylight.

Medusa Ransomware Targets Over 500 Infrastructure Orgs, Expands Tactics

Medusa ransomware has hit a staggering 500+ critical infrastructure organizations, with healthcare being a prime target, as reported in a recent FBI advisory. The attacks are happening at an alarming rate, with exploitation windows as short as 24 hours or even less.

Analyst 207
Hospital corridor with staff, equipment, and furniture, conveying disruption and concern.

Medusa Ransomware Targets Over 500 US Critical Infrastructure Orgs

The Medusa ransomware gang has struck a staggering 500+ US critical infrastructure organizations across multiple sectors, including healthcare, defense, and finance, since June 2021. This alarming surge in attacks has prompted a joint warning from top US agencies, highlighting the urgent need for heightened cybersecurity measures.

Analyst 207
Hospital corridor with people walking, computer workstation, and door in background.

Medusa Ransomware Expands Reach with New Tactics, Hundreds More Victims

The Medusa ransomware gang is on the loose, exploiting unpatched software to target hundreds of victims across various sectors, with the Healthcare and Public Health industry being a frequent hit. Now, US agencies have issued an updated warning, detailing the group's latest tactics and partnerships.

Analyst 207
Empty corporate office with computer workstations and daylight through tall windows.

Medusa Affiliate Unveils StormEncryptor Ransomware

A former Medusa affiliate, now tracked as Storm-1175, has resurfaced with a new ransomware called StormEncryptor, marking a significant shift away from Medusa and a return to malicious activity after a months-long hiatus. This development signals a fresh threat in the cybersecurity landscape.

Analyst 207
Cracked laptop screen with eerie glow, snake-like cord morphing into menacing stone face.

Microsoft Uncovers Storm-1175's Medusa Ransomware Link

Microsoft just dropped a crucial report linking Storm-1175, a notorious threat actor, to high-velocity Medusa ransomware attacks that exploit flaws in networked systems. This newly uncovered connection raises the alarm for anyone building, defending, or relying on these systems to stay vigilant against Medusa ransomware attacks.

Analyst 207
China-Linked Storm-1175 Weaponizes Zero-Days to Fuel Medusa Ransomware Blitz

China-Linked Storm-1175 Weaponizes Zero-Days to Fuel Medusa Ransomware Blitz

Medusa ransomware attacks are happening at alarming speed, thanks to a China-linked threat actor called Storm-1175 that is exploiting a potent mix of zero-day and known vulnerabilities to rapidly infect exposed systems. This high-velocity campaign is a stark reminder of the evolving ransomware threat landscape.

Analyst 207
Microsoft Ties Medusa Ransomware Gang to Zero-Day Exploits

Microsoft Ties Medusa Ransomware Gang to Zero-Day Exploits

Meet Storm-1175, a China-based cybercriminal group linked to the notorious Medusa ransomware gang, who's rapidly exploiting vulnerabilities to wreak havoc. This financially motivated group is marrying fast-moving zero-day exploits with Medusa ransomware, leading to a sharp escalation in attacks.

Analyst 207