A Medusa ransomware attack at an unnamed US organization in March 2024 involved suspicious activity across more than 80 devices, including an internet-facing domain controller. Attackers used administrative credentials, legitimate utilities and living-off-the-land techniques for reconnaissance and lateral movement, including network scanning and SMB transfers. Files were encrypted with .s3db and .MEDUSA extensions, and a Medusa ransom note was dropped. Connections to legitimate remote-management services were assessed as likely supporting data exfiltration, although that assessment does not establish confirmed data theft.
Darktrace detected and correlated the activity, but autonomous blocking was not enabled, leaving mitigation dependent on manual approval. Separate Unit 42 reporting highlighted Medusa’s escalation and a new leak site. The incident underscores the importance of restricting internet exposure of domain controllers, protecting privileged credentials, monitoring unusual SMB and remote-management activity, and ensuring high-confidence ransomware detections trigger a tested, timely containment process.

TTPs, infrastructure, and targeting history in one profile.
9 events from the most recent confirmed update back to the earliest known activity.
On March 7, the internet-facing server transferred suspicious files to multiple internal devices over SMB, targeting ADMIN$ and IPC$ shares. Attackers also wrote SQLite3 DLL files that Darktrace assessed as likely containing a payload associated with subsequent encryption.
During encryption, the attackers established SSL connections to services.pdq[.]tools, teamviewer[.]com, and anydesk[.]com. Darktrace assessed these connections as highly likely to represent attempted data exfiltration for extortion, but did not independently confirm what data was transferred.
The attackers subsequently encrypted files with the .MEDUSA extension and dropped the ransom note !!!Read_me_Medusa!!!.txt. Darktrace also observed file deletion during the attack, including deletion of files bearing the .MEDUSA extension.
During the March 2024 attack, the attackers used credentials previously observed on the network to encrypt files with the .s3db extension. Darktrace linked this activity to the suspected payload in the SQLite3 DLL files.
A few hours after scanning began on March 1, administrative connections formed a lateral-movement chain across multiple devices, including the internet-facing server. Darktrace identified three hops and linked the chain to a device involved in the earlier scanning.
Between March 1 and March 7, two devices attempted internal connections consistent with network scanning, including a request identified as evidence of Nmap use. The svc-ndscans credential was associated with DCE-RPC activity on March 1.
Darktrace identified suspicious activity at an unnamed US organization, including an internet-facing domain controller and unusual HTTP connections using PowerShell and JWrapperDownloader user agents. It correlated the activity into one investigation; autonomous blocking was not enabled, so mitigation required customer approval.
Medusa ransomware was first observed in the wild toward the end of 2022, according to Darktrace. It is distinct from MedusaLocker.
Darktrace analysts assisted the affected organization with incident triage and investigation through its Ask the Expert service.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.