medusa
· Published 20/12/2025 08:55 · Modified 21/12/2025 07:18
· Source: Ransomware.Live
Essential information
- Confidence
- 100/100
- Published
- 20/12/2025 08:55
- Modified
- 21/12/2025 07:18
- Updated at
- 21/12/2025 07:18
- Revoked
- No
- Author / Source
- Ransomware.Live
- Resource level
- —
- Primary motivation
- —
- Related entities
- 2 reports, 25 attack patterns (mitre), 4 malware, 8 sectors, 14 countries, 56 indicators, 1 vulnerabilities (cve), 6 organization
Description
No description available
Marking (TLP)
TLP:CLEAR
Labels
ransomware
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Reports (2)
-
1 CVE 11 MITREs 1 Malware 11 Observables 1 APT
-
8 MITREs 2 Malwares 50 Observables 1 APT
Attack patterns (MITRE) (25)
-
T1558.003 usesKerberoasting MITRE
-
T1589.001 usesCredentials MITRE
-
T1007 usesSystem Service Discovery MITRE
-
Firmware usesT1592.003 MITRE
-
T1021.001 usesRemote Desktop Protocol MITRE
-
T1078 usesValid Accounts MITRE
-
T1106 usesNative API MITRE
-
T1486 usesData Encrypted for Impact MITRE
-
T1568.002 usesDomain Generation Algorithms MITRE
-
T1562.001 usesDisable or Modify Tools MITRE
-
Software usesT1592.002 MITRE
-
T1190 usesExploit Public-Facing Application MITRE
Malware (4)
-
Medusa usesThe MITRE Corporation Confidence 100
[MEDUSA](https://attack.mitre.org/software/S1220) is an open-source rootkit that is capable of dynamic linker hijacking, command execution, and logging credentials.(Citation: Google Cloud Mandiant UNC3886 2024)
First seen 01/01/1970 · Last seen 16/11/5138 · -
Medusa Ransomware usesFamily
-
TangleBot usesFamily
-
ALF:Ransom:Win64/MedusaLocker uses
Sectors (8)
-
Agriculture Food Production targets
-
Public Sector targets
-
Healthcare targets
-
Finance targets
-
Technology targets
-
Manufacturing targets
-
Education targets
-
Government targets
Countries (14)
-
Australia targets
-
Indonesia targets
-
India targets
-
United Arab Emirates targets
-
United States of America targets
-
British Indian Ocean Territory targets
-
France targets
-
Canada targets
-
Portugal targets
-
United Kingdom of Great Britain and Northern Ireland targets
-
Spain targets
-
Italy targets
Indicators (56)
-
stix 100/100 Revoked· Valid until 29/09/2025 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 29/09/2025 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 29/09/2025 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 29/09/2025 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 29/09/2025 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 15/04/2025 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 29/09/2025 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 29/09/2025 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 14/09/2025 · Source: AlienVault
Vulnerabilities (CVE) (1)
9.8
Critical
Fortinet FortiClient EMS contains a SQL injection vulnerability that allows an unauthenticated attacker to execute commands as SYSTEM via specifically crafted requests.
- Attack vector
- Network
- Published
- 25/03/2024
- Modified
- 21/12/2025
Organization (6)
-
Sampoerna Agro targets
-
Resource Corporation of America targets
-
Callipo Group targets
-
Shamrock Technologies targets
-
Thunder Bay Counselling targets
-
JBS targets