Medusa Ransomware is able to disable anti-malware tools so be on your guard


  • Scientists see Medusa Ransomware -Operators that implement Smuol.SYS
  • This driver mimics a legitimate crowdstrike falcon driver
  • Medusa is actively targeting critical infrastructure organizations

Operators of Medusa Ransomware participate in old-fashioned Bring-Your-Oven-Vulnerable Driver (Byod) attacks, bypassing final point protection, detection and response (EDR) tools while installing encryption.

CyberSecurity scientists elastic security laboratories noted that the attacks start as the threat actors drop a named loader that emits two things on the target endpoint: the vulnerable driver and encryption.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top