Procedure of the Medusa hackers. The main route of infection for Medusa ransomware is targeted phishing campaigns.
Operators of the Medusa ransomware are engaging in old-fashioned bring-your-own-vulnerable-driver (BYOD) attacks, bypassing ...
The Medusa ransomware relies on a malicious Windows driver to disable the security tools running on the infected systems.
RansomHub's EDRKillShifter used in 2024 ransomware by Medusa, BianLian, and Play, revealing cross-gang tool sharing.
ESET uncovers a link between RansomHub, Play, Medusa, and BianLian ransomware gangs as more groups adopt tools to disable EDR software.
ESET researchers discover new ties between affiliates of RansomHub and of rival gangs Medusa, BianLian, and Play.
See Also: Expel: Annual Threat Report 2025 "Bring Your Own Vulnerable Driver" is a well-trod method hackers use to disable security tools and the Medusa ransomware operation has apparently taken to it ...
Ransomware actors are increasingly abusing vulnerable drivers to craft tools known as "EDR killers," which can disrupt and ...
The FBI and other federal authorities are warning healthcare organizations to safeguard against a ransomware group targeting the industry. The Medusa ransomware-as-a-service variant has been used to ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results