The Medusa Ransomware Group was hacked by security researchers, which was mainly due to the use of Rclone, a widely used tool for extracting and storing stolen data, on its Cloud Storage service.
See also: Android: New Medusa banking trojan attacks

The underlying issue arose from a malformed Rclone configuration file, which contained access tokens and other credentials, inadvertently allowing unauthorized access to the team's Cloud Storage.
Security researchers exploited this oversight to infiltrate the Medusa ransomware group's Cloud Storage, gaining access to a treasure trove of stolen data.
Upon accessing the cloud storage, researchers found that the Medusa group had stored various files from its victims, including sensitive data. They were able to not only recover but also delete critical files, mitigating potential harm to the victims.
The Rclone configuration file (conf.txt) in C:\Windows\AppCompat\ showed that the attacker used the put.io service to extract data, indicating that they used a pre-configured cloud storage account to steal data, which highlights the importance of securing cloud storage credentials and monitoring for unauthorized access.
The revelation of these bugs highlights the importance of securely configuring and carefully monitoring the tools and services that businesses use in cyberspace.
See also: Medusa ransomware group hits Victoria Racing Club
The intrusion into the Cloud Storage of the Medusa ransomware group also provided valuable information about the group's operations, methods, and objectives, which has broader implications for cybersecurity, especially regarding the importance of secure cloud storage practices and the risks of leaving sensitive information in easily accessible locations.

To prevent exploitation of similar OPSEC failures in the future, the Sigma rule aims to improve detection and response capabilities of cyber security teams.
The Medusa Ransomware Group's OPSEC failure highlights how important it is to have strong security procedures in place, particularly when handling stolen data and using cloud services.
The Dark Atlas Squad exploited a security misconfiguration (OPSEC vulnerability) in the attack against the Medusa Ransomware Group, allowing them to infiltrate Cloud Storage for a limited time and examine the data it had stolen from its victims.
The investigation revealed that the Medusa group used Rclone, a popular data extraction tool commonly used by ransomware groups, to steal data from compromised systems.
See also: Florida company hit by Medusa ransomware attack
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Ransomware attacks are one of the biggest threats in cybersecurity. In these attacks, malicious users, such as the Medusa ransomware group, encrypt data on a device or network, demanding a ransom to restore access. These attacks can cause serious damage to businesses and organizations, forcing them to invest in security and recovery measures. It is critical to implement security practices such as regular backups and training users to recognize suspicious activity in order to reduce the risk of such attacks.
Source: cybersecuritynews
