Summary
Medusa is a Ransomware-as-a-Service (RaaS) operation that targets critical infrastructure through multiple affiliates. Its attack lifecycle commonly includes exploitation of public-facing vulnerabilities, credential theft, abuse of legitimate administrative tools, and data exfiltration before ransomware deployment. The group also uses malicious drivers to disable or impair security controls and evade detection.
Investigation
The report examines the Medusa attack lifecycle and shows how operators such as Storm-1175 and Lazarus Group use different initial access vectors. Investigations highlight exploitation of GoAnywhere MFT and BeyondTrust vulnerabilities, abuse of tunneling tools like Cloudflared, and deployment of the gaze.exe ransomware payload. Researchers also observed a consistent pattern of data exfiltration before encryption.
Mitigation
Organizations should prioritize patching vulnerabilities in internet-facing systems such as GoAnywhere MFT and BeyondTrust. Strict controls should be applied to RMM and tunneling software, while east-west administrative protocols including RDP, WMI, and SMB should be restricted. Maintaining offline, immutable backups and hardening deployment infrastructure such as PDQ Deploy are also essential.
Response
If suspicious Medusa activity is detected, analysts should identify the associated user account and review source and destination peer communications. Earlier downloads, remote sessions, and file transfers should be investigated for signs of intrusion. Responders should build a timeline around the affected host and identity to distinguish legitimate administration from coordinated malicious activity.
