HomeSecurityMedusaLocker ransomware: How does it invade networks?

MedusaLocker ransomware: How does it infiltrate networks?

Several US law enforcement agencies have put the spotlight on MedusaLocker, a ransomware gang that has targeted healthcare organizations during the pandemic.

MedusaLocker

See also: Jenkins: Reveals dozens of zero-day bugs in multiple plugins

MedusaLocker emerged in 2019 and has been a problem ever since, ramping up activity during the early stages of the pandemic to maximize profits.

While Medusa is not currently as prolific as the Conti and Lockbit, MedusaLocker caused its share of trouble, being one of several threats that led to Microsoft warning healthcare providers to patch VPN endpoints and securely configure Remote Desktop Protocol (RDP).

In the first quarter of 2020, MedusaLocker was one of the top ransomware payloads along with RobbinHood, Maze, PonyFinal, Valet loader, REvil, RagnarLocker, and LockBit, according to Microsoft.

As of May 2022, Medusa has been observed primarily exploiting vulnerable RDP configurations to access victims, according to a new joint Cybersecurity Advisory (CSA) from the Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), the Treasury Department, and the Financial Crimes Enforcement Network (FinCEN).

See also: Russian hacktivists target Norway with DdoS attacks

The advisory is part of CISA's #StopRansomware collection of resources on ransomware.

"MedusaLocker appears to operate as a Ransomware-as-a-Service (RaaS) model," notes the CSA.

RaaS models involve the combined efforts of the ransomware developer and various affiliates, such as access brokers who gain initial access and other actors who deploy the ransomware on victim systems.

On a technical level, after MedusaLocker hackers gain initial access, MedusaLocker deploys a PowerShell script to spread the ransomware across the network, editing the machine's registry to identify connected hosts and networks, and using the SMB file sharing protocol to identify attached storage.

MedusaLocker attackers place a ransom note in every folder containing a file with the victim's encrypted data, according to the CSA.

MedusaLocker ransomware: How does it infiltrate networks?

See also: Ukraine: 796 cyberattacks against the country since the start of the war

The main actions of MedusaLocker after spreading across a network are as follows:

  • Restarts the LanmanWorkstation service, which allows the registry edits to be applied
  • Restarts the machine in safe mode to avoid detection by security software
  • Encrypts victim files with the AES-256 encryption algorithm
  • It runs every 60 seconds, encrypting all files except those that are important to the functionality of the victim 's machine and those that have the specified encrypted file extension
  • It establishes persistence by scheduling a task to execute the ransomware every 15 minutes.
  • Attempts to prevent standard recovery by deleting local backups, disabling startup recovery options, and deleting shadow copies

Information source: zdnet.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS