TF-MAL-apk.medusa
📛 Threat Title
Malware family: Medusa
Description
ThreatFox malware family `apk.medusa`. Printable name: Medusa. Aliases: Gorgona.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
apk.medusa
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.medusa
IOC database
- Type
- domain
- Value
apk.medusa- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-apk.medusa
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.medusa
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:cyberinsider.ca
The Medusa ransomware variant is unrelated to the MedusaLocker variant and the Medusa mobile malware variant per the FBIs investigation. FBI, CISA, and MS-ISAC encourage organizations to implement the recommendations in the Mitigations section of this advisory to reduce the likelihood and impact of Medusa ransomware incidents.
-
web:dailysecurityreview.com
A joint advisory from CISA, FBI, and MS-ISAC reveals Medusa ransomware impacted over 300 US critical infrastructure organizations by February 2025. The advisory details mitigation strategies for organizations.
-
web:go.intel471.com
Medusa Ransomware is distinct from other actors, malware , and ransomware that go by the same name, such as MedusaLocker or Medusa Botnet. The ransomware shuts down over 280 Windows services and processes, including those for mail servers, backup servers, database servers, and security software, that may prevent files from being encrypted.
-
web:www.armis.com
It details Medusa's tactics, techniques, and procedures (TTPs), indicators of compromise (IOCs), and mitigation strategies to assist organizations in defending against this evolving ransomware threat.
-
web:www.cisa.gov
The Medusa ransomware variant is unrelated to the MedusaLocker variant and the Medusa mobile malware variant per the FBI's investigation. FBI, CISA, and MS-ISAC encourage organizations to implement the recommendations in the Mitigations section of this advisory to reduce the likelihood and impact of Medusa ransomware incidents.
-
web:www.cybersecurity-review.com
The Medusa ransomware variant is unrelated to the MedusaLocker variant and the Medusa mobile malware variant per the FBI's investigation. FBI, CISA, and MS-ISAC encourage organizations to implement the recommendations in the Mitigations section of this advisory to reduce the likelihood and impact of Medusa ransomware incidents Read more…Source: U.S. Federal Bureau of Investigation Cyber ...
-
web:www.darktrace.com
Medusa ransomware increasingly exploits remote monitoring and management (RMM) tools for persistence, lateral movement, and data exfiltration. This blog explores Medusa's tactics.
-
web:www.ic3.gov
Actions for Organizations to Take Today to Mitigate Cyber Threats Related to Medusa Ransomware Activity Mitigate known vulnerabilities by ensuring operating systems, software, and firmware are patched and up to date within a risk-informed span of time. Segment networks to restrict lateral movement from initial infected devices and other devices in the same organization. Filter network traffic ...
-
web:www.microsoft.com
The financially motivated cybercriminal threat actor Storm-1175 operates high-velocity ransomware campaigns that weaponize recently disclosed vulnerabilities to obtain initial access, exfiltrate data, and deploy Medusa ransomware.
-
web:www.picussecurity.com
Medusa ransomware emerged as Ransomware-as-a-Service in June 2021 and gained infamy by compromising over 300 victims from critical infrastructure sectors, including healthcare, insurance, technology, manufacturing, legal, and technology.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.