Several US law enforcement agencies have put the spotlight on MedusaLocker, a ransomware gang that has targeted healthcare organizations during the pandemic.

See also: Jenkins: Reveals dozens of zero-day bugs in multiple plugins
MedusaLocker emerged in 2019 and has been a problem ever since, ramping up activity during the early stages of the pandemic to maximize profits.
While Medusa is not currently as prolific as the Conti and Lockbit, MedusaLocker caused its share of trouble, being one of several threats that led to Microsoft warning healthcare providers to patch VPN endpoints and securely configure Remote Desktop Protocol (RDP).
In the first quarter of 2020, MedusaLocker was one of the top ransomware payloads along with RobbinHood, Maze, PonyFinal, Valet loader, REvil, RagnarLocker, and LockBit, according to Microsoft.
As of May 2022, Medusa has been observed primarily exploiting vulnerable RDP configurations to access victims, according to a new joint Cybersecurity Advisory (CSA) from the Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), the Treasury Department, and the Financial Crimes Enforcement Network (FinCEN).
See also: Russian hacktivists target Norway with DdoS attacks
The advisory is part of CISA's #StopRansomware collection of resources on ransomware.
"MedusaLocker appears to operate as a Ransomware-as-a-Service (RaaS) model," notes the CSA.
RaaS models involve the combined efforts of the ransomware developer and various affiliates, such as access brokers who gain initial access and other actors who deploy the ransomware on victim systems.
On a technical level, after MedusaLocker hackers gain initial access, MedusaLocker deploys a PowerShell script to spread the ransomware across the network, editing the machine's registry to identify connected hosts and networks, and using the SMB file sharing protocol to identify attached storage.
MedusaLocker attackers place a ransom note in every folder containing a file with the victim's encrypted data, according to the CSA.

See also: Ukraine: 796 cyberattacks against the country since the start of the war
The main actions of MedusaLocker after spreading across a network are as follows:
- Restarts the LanmanWorkstation service, which allows the registry edits to be applied
- Restarts the machine in safe mode to avoid detection by security software
- Encrypts victim files with the AES-256 encryption algorithm
- It runs every 60 seconds, encrypting all files except those that are important to the functionality of the victim 's machine and those that have the specified encrypted file extension
- It establishes persistence by scheduling a task to execute the ransomware every 15 minutes.
- Attempts to prevent standard recovery by deleting local backups, disabling startup recovery options, and deleting shadow copies
Information source: zdnet.com
