A new version of the Medusa DDoS (distributed denial of service) botnet has appeared, based on the Mirai code, featuring a ransomware module and a Telnet brute-forcer.

See also: GoAnywhere MFT zero-day: Fortra released patch
Medusa is an old malware strain (not to be confused with the Android trojan) advertised on darknet marketplaces since 2015, which later added HTTP-based DDoS capabilities in 2017.
Cyble shared with BleepingComputer that it has identified a new variant of an established malware strain. The latest version is based on the leaked Mirai botnet source code, inheriting Linux targeting capabilities and extensive DDoS attack options.
Taking it a step further, Medusa has now emerged as a MaaS (malware-as-a-service) platform that provides DDoS or mining solutions through its own portal. Notable features of the service include enhanced stability, complete anonymity for users, helpful technical support whenever needed, user-friendly API , and adjustable pricing depending on the client’s requirements.
See also: Clop ransomware for Linux: Flaw allows file recovery

Ransomware functionality
In this new Medusa variant, there is an interesting ransomware feature that allows it to explore all directories for viable file types to encrypt. Generally, these targeted files include documents and vector design files.

Valid files are encrypted using 256-bit AES encryption, and the .medusastealer extension is appended to the name of the encrypted files.

However, the encryption method appears broken, turning the ransomware into a data wiper.
After encrypting files on a device, the malware remains dormant for 24 hours before deleting all stored documents on the system drives.
After deleting essential files, a ransom note will appear demanding 0.5 BTC ($11,400) as payment – an unreasonable demand for any successful extortion attempt.

Cyble believes this is a coding error because it corrupts system drives, making it impossible for victims to use their systems or read the ransom note. This error also suggests that the new Medusa variant , or at least this feature, is still under development.
It's worth noting that while the new version of Medusa features a data extraction tool, it doesn't steal user files before encryption. Instead, it focuses on gathering basic system information that helps identify victims and estimate resources that can be used for mining and DDoS attacks.

Telnet attacks
Additionally, Medusa has a brute-forcing feature that attempts to gain access to devices connected to the internet with commonly used usernames and passwords. If successful, it will then download an additional payload that Cyble has not yet been able to recover or analyze.
See also: Researcher hacked Toyota's GSPIMS application
Medusa then runs the “zmap” command to discover other devices with Telnet services running on port 23. It then attempts to connect to them using the IP addresses it receives in combination with a series of usernames and passwords.
Finally, upon establishing a Telnet connection, the malware infects the system with the main Medusa payload (“infection_medusa_stealer”).

The final Medusa payload also has incomplete support for receiving the “FivemBackdoor” and “sshlogin” commands.
Furthermore, the code associated with this program is noticeably absent from the client's Python file – another indication that this program is still a work in progress.
Information source: bleepingcomputer.com
