US cybersecurity officials warn against potentially costly Medusa ransomware attacks


FILE - This June 14, 2018 file photo shows an FBI seal on a podium before a news conference at the agency's headquarters in Washington. (AP Photo/Jose Luis Magana, File)

LOS ANGELES: The FBI and the US Cybersecurity and Infrastructure Security Agency are warning against a dangerous ransomware scheme.

In an advisory posted earlier this week, government officials warned that a ransomware-as-a-service software called Medusa, which has launched ransomware attacks since 2021, has recently affected hundreds of people. Medusa uses phishing campaigns as its main method for stealing victims' credentials, according to CISA.

To protect against the ransomware, officials recommended patching operating systems, software and firmware, in addition to using multifactor authentication for all services such as email and VPNs. Experts also recommended using long passwords, and warned against frequently recurring password changes because they can weaken security.

Medusa developers and affiliates – called "Medusa actors” – use a double extortion model, where they "encrypt victim data and threaten to publicly release exfiltrated data if a ransom is not paid”, the advisory said. Medusa operates a data-leak site that shows victims alongside countdowns to the release of information.

"Ransom demands are posted on the site, with direct hyperlinks to Medusa affiliated cryptocurrency wallets,” the advisory said. "At this stage, Medusa concurrently advertises sale of the data to interested parties before the countdown timer ends. Victims can additionally pay US$10,000 (RM44,465) in cryptocurrency to add a day to the countdown timer.”

Since February, Medusa developers and affiliates have hit more than 300 victims across industries, including the medical, education, legal, insurance, technology and manufacturing sectors, CISA said. – AP

Follow us on our official WhatsApp channel for breaking news alerts and key updates!

Next In Tech News

Google Chrome worth ‘upwards of US$50bil’, browser rival says
Google blocked Motorola use of Perplexity AI, witness testifies
UK to ban 'sim farms' used by scammers to send mass fraud messages
WhatsApp rolls out new privacy tools to block chat exports, media auto-downloads, and AI message use
Here's how to check if you were selected for National Service online
At Meta’s landmark trial, a stroll through a graveyard of dead apps
YouTube says more than 20 billion videos uploaded in 20 years
Revolut profit soars to $1.5 billion as Storonsky increases stake to more than 25%
Why China’s robot makers are unfazed by US tariffs: ‘We’re the only supplier’
STMicro sees better quarterly sales after bottom-of-year 1st quarter

Others Also Read