Medusa ransomware encrypted hosts in an unmonitored subdomain of a North American organization in an incident investigated by ReliaQuest in June 2024. The suspected intrusion began in early April through a compromised customer VPN account, followed by network discovery and credential dumping from LSASS and Active Directory. Attackers subsequently used compromised administrative credentials for RDP lateral movement, installed remote-access tools, and abused PDQ tooling to deploy ransomware. A suspected vulnerable driver apparently helped bypass endpoint protection. Fragmented domains, legacy systems, and visibility gaps complicated investigation and response.
ReliaQuest recommended stronger VPN authentication, network segmentation, comprehensive endpoint monitoring, least privilege, and tested recovery plans. Microsoft's additional LSA protection guidance and Credential Guard documentation provide complementary credential-hardening measures. Credential Guard uses virtualization-based security to isolate NTLM hashes, Kerberos ticket-granting tickets, and certain stored domain credentials, helping mitigate pass-the-hash and pass-the-ticket attacks even when malware has administrative privileges. It does not stop all persistent threat activity or replace detection and containment controls. Deployment requires hardware, licensing, and application compatibility checks; Microsoft does not recommend or support enabling Credential Guard on domain controllers or Exchange Server.

TTPs, infrastructure, and targeting history in one profile.
14 events from the most recent confirmed update back to the earliest known activity.
ReliaQuest responded in June 2024 to EDR detections associated with the attack. Fragmented domains, legacy systems, and gaps in endpoint visibility impeded the investigation and response.
Successful encryptor deployment followed the suspected driver activity, encrypting multiple hosts in the North American organization's unmonitored subdomain. The ransom note !!!READ_ME_MEDUSA!!!.txt was written to affected hosts.
Investigators subsequently detected C:\WINDOWS\TEMP\igJTf.sys. ReliaQuest assessed it as a vulnerable driver likely intended for kernel-level installation to unhook antivirus protection.
Within an hour of the PDQ Inventory installations, investigators observed PDQDeploy logons and antivirus detections that blocked gaze.exe. The executable carried a Medusa-related signature.
On the same day as the AnyDesk installation, the attacker used a compromised administrative account to install the PDQInventory-Scanner-1 service on multiple hosts.
The attacker installed AnyDesk on a target server within minutes of the observed RDP connection. ReliaQuest assessed the installation as redundant command-and-control access intended to maintain the foothold before encryption.
At the beginning of June, investigators confirmed RDP lateral movement through type 10 logons using a compromised administrative account. A connection originated from a domain controller and used a same-named account from another domain.
Exported Windows System logs showed SimpleHelp remote-monitoring-and-management service installations on a target host dating back to mid-May.
In May, the attacker used lsassy to locate LSASS and invoke comsvcs.dll through rundll32.exe to dump in-memory credentials.
Within a day of the first VPN session, investigators identified an LSASS-dumping attempt from a VPN-assigned address and an NTDS-dumping attempt on a domain controller. The latter used PowerShell and ntdsutil to create an Active Directory database snapshot and copy registry hives for password-hash extraction.
Within an hour of the initial VPN session, firewall traffic from the assigned internal address resembled port scanning against multiple destinations. The activity continued for several hours.
Investigators identified an anomalous VPN session in early April 2024 using a customer domain account from Russian IP address 178.208.87.250. The session received an address in a legacy customer-access subnet; investigators could not determine how the credentials were obtained.
Medusa introduced its data leak site in early 2023 to publish information about its victims.
Security researchers first identified Medusa as a ransomware-as-a-service operator in late 2022. The report distinguishes it from the separate MedusaLocker ransomware operation.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.