s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.medusa

📛 Threat Title

Malware family: Medusa

Category: Medusa First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.medusa`. Printable name: Medusa. Aliases: Gorgona.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.medusa VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.medusa

IOC database

Type
domain
Value
apk.medusa
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.medusa

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.medusa

References (1)

Remediations (10)

  • web:cyberinsider.ca

    The Medusa ransomware variant is unrelated to the MedusaLocker variant and the Medusa mobile malware variant per the FBIs investigation. FBI, CISA, and MS-ISAC encourage organizations to implement the recommendations in the Mitigations section of this advisory to reduce the likelihood and impact of Medusa ransomware incidents.

  • web:dailysecurityreview.com

    A joint advisory from CISA, FBI, and MS-ISAC reveals Medusa ransomware impacted over 300 US critical infrastructure organizations by February 2025. The advisory details mitigation strategies for organizations.

  • web:go.intel471.com

    Medusa Ransomware is distinct from other actors, malware , and ransomware that go by the same name, such as MedusaLocker or Medusa Botnet. The ransomware shuts down over 280 Windows services and processes, including those for mail servers, backup servers, database servers, and security software, that may prevent files from being encrypted.

  • web:www.armis.com

    It details Medusa's tactics, techniques, and procedures (TTPs), indicators of compromise (IOCs), and mitigation strategies to assist organizations in defending against this evolving ransomware threat.

  • web:www.cisa.gov

    The Medusa ransomware variant is unrelated to the MedusaLocker variant and the Medusa mobile malware variant per the FBI's investigation. FBI, CISA, and MS-ISAC encourage organizations to implement the recommendations in the Mitigations section of this advisory to reduce the likelihood and impact of Medusa ransomware incidents.

  • web:www.cybersecurity-review.com

    The Medusa ransomware variant is unrelated to the MedusaLocker variant and the Medusa mobile malware variant per the FBI's investigation. FBI, CISA, and MS-ISAC encourage organizations to implement the recommendations in the Mitigations section of this advisory to reduce the likelihood and impact of Medusa ransomware incidents Read more…Source: U.S. Federal Bureau of Investigation Cyber ...

  • web:www.darktrace.com

    Medusa ransomware increasingly exploits remote monitoring and management (RMM) tools for persistence, lateral movement, and data exfiltration. This blog explores Medusa's tactics.

  • web:www.ic3.gov

    Actions for Organizations to Take Today to Mitigate Cyber Threats Related to Medusa Ransomware Activity Mitigate known vulnerabilities by ensuring operating systems, software, and firmware are patched and up to date within a risk-informed span of time. Segment networks to restrict lateral movement from initial infected devices and other devices in the same organization. Filter network traffic ...

  • web:www.microsoft.com

    The financially motivated cybercriminal threat actor Storm-1175 operates high-velocity ransomware campaigns that weaponize recently disclosed vulnerabilities to obtain initial access, exfiltrate data, and deploy Medusa ransomware.

  • web:www.picussecurity.com

    Medusa ransomware emerged as Ransomware-as-a-Service in June 2021 and gained infamy by compromising over 300 victims from critical infrastructure sectors, including healthcare, insurance, technology, manufacturing, legal, and technology.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.