EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to intelligence
Ransomware

#StopRansomware: Medusa Ransomware

Official source
EudorIA operational summary

What it means

Priority 95/100

CISA Cybersecurity Advisories ha pubblicato un advisory sul ransomware Medusa. La fonte descrive vulnerabilita o tecniche gia osservate in attacchi e richiede una verifica prioritaria.

Why it matters

L'advisory descrive attivita ransomware osservate e misure difensive pubblicate da un'autorita. Non prova che il proprio perimetro sia compromesso, ma richiede una verifica prioritaria di esposizione e controlli.

Potential operational benefits

  • Prioritizzazione delle esposizioni Internet e delle vulnerabilita sfruttate
  • Verifica dei controlli su accessi remoti, movimento laterale ed esfiltrazione
  • Validazione documentata della capacita di ripristino
Indications to confirm against the customer's technical and organisational perimeter.
Relevant controlsVulnerability managementIdentity and access managementNetwork segmentationBackup and recoveryDetection and response
AudienceITSOCCISOManagement
Information centre

Translation in progress

CISA

The official content is available in the original language. The Italian version will be published once automated checks are complete.

Text acquired from the source

Cybersecurity Advisory #StopRansomware: Medusa Ransomware Last Revised August 18, 2026 Alert Code AA25-071A Related topics: Cybersecurity Best Practices , Organizations and Cyber Safety , Critical Infrastructure Security and Resilience Advisory at a Glance Title #StopRansomware: Medusa Ransomware Original Publication March 12, 2025 Last Update Aug. 18, 2026 Executive Summary The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and U.S. Department of Health and Human Services (HHS) are releasing this updated joint advisory to disseminate known Medusa ransomware tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) identified through FBI investigations as recently as April 2026. Medusa is a ransomware-as-a-service (RaaS) variant first identified in June 2021. Both Medusa developers and affiliates use a double-extortion model where they encrypt victim data and threaten to publicly release exfiltrated data if a ransom is not paid. Last Update Description The update expands details on Medusa actors’ operations, including more specifics about their affiliate model and payment ranges for initial access brokers, as well as a broader list of exploited vulnerabilities. It describes Medusa’s opportunistic targeting and use of Interactsh URLs for exploit verification. It also lists additional tools for network enumeration, persistence, and stealth, including detailed PowerShell obfuscation techniques and command-and-control utilities. Additionally, HHS has been added as a co-sealer, providing their insights into Medusa’s operations against the Healthcare and Public Health Sector. Key Actions Mitigate known vulnerabilities by ensuring operating systems, software, and firmware are patched and up to date within a

Indicatori CISA verificabili

52 valori IOC dalla fonte ufficiale. Non sono una lista di blocco automatica: verificare data, contesto e applicabilita.

Ultima verifica: 2026-09-25T23:03:07.131911+00:00

Scarica STIX 2.1
TipoIndicatore (non cliccabile)File
email-addrmedusasupport[@]cock[.]li
email-addrmds[.]svt[.]mir2[@]protonmail[.]com
email-addrmds[.]svt[.]breach[@]protonmail[.]com
MD580d852cd199ac923205b61658a9ec5bc
SHA-145d89fe2c554d1dd2ac3a8879965b35ed7e3421f
SHA-256baa980ae253101066ae7e551a354116454e8697ff2154a907c9885770cdae4ae
email-addrmedusa[.]support[@]onionmail[.]org
MD544370f5c977e415981febf7dbb87a85c
SHA-1ac0dce3b0f5b8d187a2e3f29efc358538fd4aa45
SHA-25656b08aa03bd8c0ea094cfeb03d5954ffd857bac42df929dc835eea62f32b09e0
SSDEEP6:6IsxYToXhLPxFmGSS3HBd1zOxAWpTPm/k/KnqbKADUQapLj/662:wQotxnxM/BbTDpapLj//2
email-addrkey[.]medusa[.]serviceteam[@]protonmail[.]com

Provenance

Allegato ufficiale CISA · 2025-03-03T17:17:09Z

SHA-512: c60420331608fa8491520640347bed09377a0c1c7b764544a1171795a294ca6440deceebb8cf9ed95b75eebbbd5cc5ea78f58fb24d0fcdd2e1f3e8614039b456

TipoIndicatore (non cliccabile)File
email-addrkey[.]medusa[.]serviceteam[@]protonmail[.]com
email-addrmds[.]svt[.]breach[@]protonmail[.]com
SHA-1ac0dce3b0f5b8d187a2e3f29efc358538fd4aa45
SHA-25656b08aa03bd8c0ea094cfeb03d5954ffd857bac42df929dc835eea62f32b09e0
MD544370f5c977e415981febf7dbb87a85c
SSDEEP6:6IsxYToXhLPxFmGSS3HBd1zOxAWpTPm/k/KnqbKADUQapLj/662:wQotxnxM/BbTDpapLj//2
email-addrmedusa[.]support[@]onionmail[.]org
email-addrmds[.]svt[.]mir2[@]protonmail[.]com
SHA-145d89fe2c554d1dd2ac3a8879965b35ed7e3421f
SHA-256baa980ae253101066ae7e551a354116454e8697ff2154a907c9885770cdae4ae
MD580d852cd199ac923205b61658a9ec5bc
email-addrmedusasupport[@]cock[.]li

Provenance

Allegato ufficiale CISA · 2025-03-06T00:00:00Z

SHA-512: 523a75008ad69041fdea1639c297bd064dc9f6aadb6b084718c6155be626698d487b361f4fe17b36513b8fe5bfc7ebb607ceccfbfbd77d10f389e791739cbf24

TipoIndicatore (non cliccabile)File
SHA-12df705c9be0465f1c73a9f5d35147723deb16b5eMain_new.exe
ipv4-addr37[.]221[.]66[.]239
ipv4-addr143[.]244[.]47[.]89
domain-nameerp[.]ranasons[.]com
ipv4-addr185[.]238[.]231[.]85
ipv4-addr185[.]238[.]231[.]77
ipv4-addr185[.]238[.]231[.]4
ipv4-addr185[.]238[.]231[.]98
ipv4-addr155[.]2[.]215[.]69
ipv4-addr37[.]19[.]21[.]180
ipv4-addr23[.]234[.]93[.]112
ipv4-addr23[.]234[.]106[.]242
ipv4-addr155[.]2[.]215[.]71
ipv4-addr146[.]70[.]172[.]247
ipv4-addr23[.]234[.]89[.]195
ipv4-addr185[.]238[.]231[.]16
ipv4-addr143[.]110[.]243[.]154
ipv4-addr167[.]88[.]166[.]173
MD58f11d9067da087cb4185fa804caac2df
urlhttps://3324[.]requestcatcher[.]com/hihi
ipv4-addr94[.]156[.]67[.]145
ipv4-addr45[.]61[.]150[.]94
urlhttp://45[.]61[.]150[.]94:8000/storm[.]exe
MD54d0b6e3c9c33550a005e41663a1977cbnezha-agent.exe
SHA-175482072f71b5457351fe3fddcd1379608767c00nezha-agent.exe
SHA-256d3abd4bae082d4c9918447fe82c521567cc7f9b0e5f2d55999a6e5c40fa7fd54nezha-agent.exe
SSDEEP98304:0/Pt4oB9mz2B7awbDFSzmfLHG7iXnkr/K1nJFGfUpojhnbpet4IAddKf6ELWcE+H:0XJmzCawbDsKz84nkmvFG2Wee8Acwsnezha-agent.exe
MD5d796259c44be852327623fd2e40c47f2def.exe
SHA-1ad5d8dca6ad20b3b9d3b3bd5b2bbb795205f1109def.exe
SHA-256a5a3c3c4fbf5c7db808176db3242c2106995c85f8ba987472ea0e92e59503b55def.exe
MD52c7f328feeb94608aaaf99ec70cb0323j.exe
SHA-256b29defbbc4ebaa243c1712ccc4943374f1b6fb864c39ed9f70fceb17eee098dbRunFileCopy.cmd
SHA-25604b13b6cd5e5291b1cde78975a140feea7fd3bc3777c53caa1ab33426c83bfcccommand.cmd
ipv4-addr185[.]135[.]86[.]185
ipv4-addr85[.]155[.]186[.]121
ipv4-addr83[.]138[.]53[.]139
MD5eb05429d25fc57b476428cdb0a134b2fmimilib.dll
SHA-11c6913248131b5784b923eff1e76a443f738affcmimilib.dll
SHA-2567ffce7f6d7262f214d78e6b7fd8d07119835cba4b04ce334260665d7c8fb369amimilib.dll
SSDEEP768:VWZZrWUCE5KuhECg1kQPbTk/Zm8b4snsFYzltrf0zlejdl0mHFBEhLF3YEhV7K:gP1vgKob4/Zm8bxsFmGlejdl5lBE/IE+mimilib.dll
MD544370f5c977e415981febf7dbb87a85copenrdp.bat
SHA-1ac0dce3b0f5b8d187a2e3f29efc358538fd4aa45openrdp.bat
SHA-25656b08aa03bd8c0ea094cfeb03d5954ffd857bac42df929dc835eea62f32b09e0openrdp.bat
SSDEEP6:6IsxYToXhLPxFmGSS3HBd1zOxAWpTPm/k/KnqbKADUQapLj/662:wQotxnxM/BbTDpapLj//2openrdp.bat

Provenance

Allegato ufficiale CISA · 2026-08-14T14:21:33Z

SHA-512: 18e26efc345e2c754fd5e8f0238a208f3a9913d0f0e5439a9d856022a26db9b55ec2f83af686716246e8719ed4aecb774f6175c1b2729f11db83d99e44601d2c

Source
CISA Cybersecurity Advisories
Publishing entity
CISA
Entity type
National authority
Area
North America · US
Original language
en · translation in preparation
Publication
18/08/2026 14:00
Sharing
TLP:CLEAR
MITRE ATT&CK
T1003.001, T1006, T1016, T1021.001, T1027, T1027.013, T1033, T1046, T1047, T1049, T1059.001, T1059.003, T1069.002, T1070, T1070.003, T1071.001, T1072, T1082, T1083, T1105, T1135, T1136.002, T1190, T1218.014, T1219, T1484.001, T1486, T1489, T1490, T1529, T1558, T1562.001, T1564.012, T1566, T1567.002, T1569.002, T1657, T1675, T1685
CVE
CVE-2024-1709, CVE-2023-48788, CVE-2025-10035, CVE-2026-1731
Classification
Critical
Group attributed by the source
Medusa
Stated country
US
Technical scope

Affected products and versions

Verification in progress
Information not yet acquired.

The collector will check NVD and the available official vendor advisories.

Action indicated by the source

Verificare e correggere con priorita i sistemi Internet-facing indicati dalla fonte; applicare MFA resistente al phishing, segmentazione e backup offline immutabili con prove di ripristino.

Official technical references

Open the original source