Medusa: The Ransomware
Overview Medusa, also known as MedusaLocker, is a ransomware discovered in 2019. It operates in a ransomware-as-a-service (RaaS) business model and goes for double extortion tactic stealing the victim's data before encryption. It mainly targets big organizations with high volumes of Personal Identifiable Information (PII), health sector, and educational sectors. Medusa generally gain access via brute-force attacks on Remote Desktop Protocol (RDP), leaked RDP credentials, or spear-phishing attacks to steal user credentials. Understanding Medusa Since its discovery, Medusa have seen drastic changes in its ransomware activities and extortion tactics. They have even launched their dedicated leak site in early 2023, called the Medusa Blog, where they disclose sensitive data of the victims who does not comply with their demands. They employ a multi-extortion strategy and offer multiple options to their victims. All the options such as time extension, data deletion, or download of all