#StopRansomware: Medusa Ransomware
2025-03-12 • USCISA •
https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-071a
Attachments
Medusa ransomware developers and affiliates had affected more than 500 victims across multiple critical-infrastructure sectors by April 2026, with healthcare organizations among their frequent targets. The operation obtains access through phishing, initial-access brokers, and rapid exploitation of vulnerabilities, then uses credential dumping, remote-management tools, Rclone, and the Gaze encryptor for lateral movement, exfiltration, and encryption. Its double-extortion model combines encrypted systems with threats to publish or sell stolen data, while one FBI-investigated case suggested either triple extortion or operational conflict among affiliates.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 2df705c9be0465f1c73a9f5d3514772… | 2025-03-12 | 2025-03-12 |
| HASH | 8f11d9067da087cb4185fa804caac2df | 2025-03-12 | 2025-03-12 |
| HASH | 44370f5c977e415981febf7dbb87a85c | 2025-03-12 | 2025-03-12 |
| HASH | f1b6fb864c39ed9f70fceb17eee098db | 2025-03-12 | 2025-03-12 |
| HASH | b29defbbc4ebaa243c1712ccc4943374 | 2025-03-12 | 2025-03-12 |
| HASH | a7fd3bc3777c53caa1ab33426c83bfcc | 2025-03-12 | 2025-03-12 |
| HASH | 04b13b6cd5e5291b1cde78975a140fee | 2025-03-12 | 2025-03-12 |
| HASH | eb05429d25fc57b476428cdb0a134b2f | 2025-03-12 | 2025-03-12 |
| HASH | 4d0b6e3c9c33550a005e41663a1977cb | 2025-03-12 | 2025-03-12 |
| HASH | d796259c44be852327623fd2e40c47f2 | 2025-03-12 | 2025-03-12 |
| HASH | 2c7f328feeb94608aaaf99ec70cb0323 | 2025-03-12 | 2025-03-12 |
| IPv4 | 94.156.67.145 | 2025-03-12 | 2025-03-12 |
| URL | http://45.61.150.94:8000/storm.… | 2025-03-12 | 2025-03-12 |
| IPv4 | 85.155.186.121 | 2025-03-12 | 2025-03-12 |
| IPv4 | 185.238.231.85 | 2025-03-12 | 2025-03-12 |
| IPv4 | 185.238.231.77 | 2025-03-12 | 2025-03-12 |
| IPv4 | 185.238.231.4 | 2025-03-12 | 2025-03-12 |
| IPv4 | 83.138.53.139 | 2025-03-12 | 2025-03-12 |
| IPv4 | 185.135.86.185 | 2025-03-12 | 2025-03-12 |
| IPv4 | 37.221.66.239 | 2025-03-12 | 2025-03-12 |
| IPv4 | 185.238.231.98 | 2025-03-12 | 2025-03-12 |
| IPv4 | 155.2.215.69 | 2025-03-12 | 2025-03-12 |
| IPv4 | 37.19.21.180 | 2025-03-12 | 2025-03-12 |
| IPv4 | 23.234.93.112 | 2025-03-12 | 2025-03-12 |
| IPv4 | 23.234.106.242 | 2025-03-12 | 2025-03-12 |
| IPv4 | 155.2.215.71 | 2025-03-12 | 2025-03-12 |
| IPv4 | 146.70.172.247 | 2025-03-12 | 2025-03-12 |
| IPv4 | 23.234.89.195 | 2025-03-12 | 2025-03-12 |
| IPv4 | 185.238.231.16 | 2025-03-12 | 2025-03-12 |
| DOMAIN | erp.ranasons.com | 2025-03-12 | 2025-03-12 |
| IPv4 | 143.110.243.154 | 2025-03-12 | 2025-03-12 |
| URL | https://3324.requestcatcher.com… | 2025-03-12 | 2025-03-12 |
| IPv4 | 167.88.166.173 | 2025-03-12 | 2025-03-12 |
| IPv4 | 143.244.47.89 | 2025-03-12 | 2025-03-12 |