The Philippine Health Insurance Corporation has temporarily disabled its Medusa ransomware-affected IT system.
See also: Zanubis: Android banking trojan becomes even more dangerous

See also: What are the most common Facebook scams?
The Philippine Health Insurance Corporation recently announced that it suffered a cyberattack on its IT system.
According to a news report, the attack that took place on the morning of September 22nd was by the Medusa ransomware.
The state-run health fund has not yet said which parts of its systems were affected, but it is currently investigating the extent of the attack while implementing mitigation measures, such as temporarily disabling the compromised systems. PhilHealth currently has 65 million active contributors.
See also: Lazarus hackers breach aerospace company with new LightlessCan malware
Medusa ransomware is a type of fileless ransomware that is typically delivered via spear-phishing or exploit kits. Once it enters a network, it uses a number of sophisticated techniques to evade detection and spread. For example, it may use process hollowing, where it injects malicious code into a legitimate system to hide its own activities. Another technique is file-less execution, where it executes directly in memory to avoid leaving a trace on the disk. Once it has successfully established its presence, Medusa uses encryption to lock down files and make them inaccessible to the user.
Information source: healthcareitnews.com
