menu
techminis

A naukri.com initiative

google-web-stories
Home

>

Technology News

>

Medusa ran...
source image

Tech Radar

3w

read

402

img
dot

Image Credit: Tech Radar

Medusa ransomware is able to disable anti-malware tools, so be on your guard

  • The Medusa ransomware operators are using a vulnerable driver named smuol.sys which mimics a legitimate CrowdStrike Falcon driver named CSAgent.sys.
  • The driver has been signed by a Chinese vendor called ABYSSWORKER.
  • Medusa ransomware is targeting critical infrastructure organizations and is actively engaged in BYOD attacks bypassing endpoint protection, detection, and response (EDR) tools.
  • The FBI, CISA, and MS-ISAC have already issued a warning and recommend implementing the necessary mitigations.

Read Full Article

like

24 Likes

For uninterrupted reading, download the app