Ep. 75 - The Franchise Model: How Medusa Turned Ransomware Into a Business
Medusa ransomware has went from 300 victims to more than 500, and CISA, FBI, and MS-ISAC just refreshed advisory AA25-071A with new IOCs and TTPs.
Tova Dvorin and Adrian Culley unpack the ransomware-as-a-service franchise behind it: the ScreenConnect and Fortinet EMS CVEs still opening doors, three tiers of PowerShell obfuscation, gaze.exe killing shadow copies before AES-256 encryption, and the triple-extortion case where one victim was made to pay twice.
Plus, learn how to validate your controls against each technique instead of assuming they catch it.
Timestamps:
00:00 Intro: Medusa Ransomware Advisory
00:42 What Is Medusa Ransomware?
01:24 How Many Medusa Victims Are There Now?
02:04 How Does Medusa Operate as a Business?
A franchise: affiliates recruited on criminal forums for $100 to $1 million per engagement do the breaking in, while the core developers keep ransome negotiation centrally controlled.
02:55 How Do Medusa Affiliates Gain Initial Access?
03:55 What Does “Living off the Land” Actually Mean?
03:26 How Does Medusa Avoid Detection?
04:53 How Elaborate Is Medusa’s PowerShell Obfuscation?
05:56 How Does Medusa Move Laterally?
07:35 What Does PsExec Do Once They Harvest Credentials?
With valid credentials, PsExec gives them system-level execution on remote machines three ways: copy a batch script over and run it, run a file already on that host, or fire arbitrary shell commands with cmd /c. The named example is openrdp.bat, which opens the firewall for inbound RDP on 3389, enables remote WMI, and flips a registry key to allow remote desktop — turning a locked-down machine into a foothold.
09:30 What Happens During Medusa’s Encryption Phase?
11:10 How Does Medusa Extortion Work?
11:49 Is Triple Extortion Happening?
12:40 Why Does This Advisory Matter?
13:30 Where Should Defenders Start?
14:11 Why Do Immutable Backups Matter?
15:10 What’s the Best Testing Approach?
Read the full blog here: https://www.safebreach.com/blog/safebreach-coverage-us-cert-aa25-071a-medusa-ransomware/
#cybersecurity #infosec #CISO #MedusaRansomware #ransomware #CISAadvisory #BAS #cyberresilience