CISA, FBI Warn of Medusa Ransomware Impacting Critical Infrastructure
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-48788 | Unauthenticated SQL Injection in Fortinet FortiClient EMS Fortinet FortiClient EMS — the central management server for FortiClient endpoint deployments — contains a SQL injection flaw (CWE-89) in versions 7.0.1 through 7.0.10 and 7.2.0 through 7.2.2. The CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N) shows it can be triggered remotely with no credentials and no user interaction: an unauthenticated attacker sends specially crafted packets to the vulnerable management server and can execute unauthorized code or commands. Successful exploitation effectively yields remote code execution on the EMS server and access to its database, enabling follow-on actions such as credential theft, abuse of endpoint management functions, and ransomware deployment. Any organization running the affected EMS versions is exposed, especially where the management server is reachable from the internet. Exploitation is confirmed in the wild: CISA added the bug to the KEV catalog on 2024-03-25 with known ransomware use, and EPSS assigns a ~98.4% probability of exploitation within 30 days (100th percentile). Do: Upgrade FortiClient EMS to the fixed releases per Fortinet's advisory for this CVE (7.2.3 and 7.0.11 or later, i.e., beyond the 7.2.2 and 7.0.10 affected ranges); the CISA KEV required action is to apply vendor mitigations or discontinue use if mitigations are unavailable. Until patched, limit exposure of the EMS web interface to untrusted networks and hunt for signs of compromise — anomalous requests to the management console, unexpected database or admin activity, and follow-on ransomware behavior — since exploitation with known ransomware use is confirmed. | 9.8 | 98% | KEV ransomware |
| largetens of thousands of EMS deployments worldwide, with a smaller subset (likely thousands) internet-exposed | |
| CVE-2024-1709 | Authentication Bypass in ConnectWise ScreenConnect Creates Rogue Admin Accounts ConnectWise ScreenConnect (ConnectWise Control), a widely used remote-access and remote-monitoring tool, contains an authentication bypass (CWE-288) in its management interface. An attacker needs only network access to the management interface to trigger the flaw, with no valid credentials or user interaction required. A successful attacker gains administrative control of the ScreenConnect server by creating a new administrator-level account, providing a foothold that has already been used in ransomware campaigns against downstream managed environments. Any organization running ConnectWise ScreenConnect is affected, especially managed service providers and IT teams whose management interface is reachable from the internet; the source data specifies affected products but no version ranges. Exploitation is confirmed and urgent: CISA added the flaw to the KEV on 2024-02-22 with known ransomware use, EPSS assigns a 100% probability of exploitation within 30 days, and ConnectWise warned that no patch was available at the time of disclosure. Do: Follow ConnectWise's instructions immediately: no patch existed at disclosure, so apply the vendor's mitigations or, per the CISA KEV required action, restrict internet exposure of the management interface or discontinue use until mitigations are available, then upgrade to the vendor's patched release as soon as it ships. Audit ScreenConnect servers for unexpectedly created administrator-level accounts and unusual remote sessions, which are the attack's artifacts. Prioritize any instance whose management interface is reachable from the internet, given confirmed in-the-wild exploitation and known ransomware use. | 10.0 | 100% | KEV ransomware PoC ×3 |
| masstens of thousands of internet-exposed ScreenConnect servers (on the order of 10,000-30,000 instances in public internet scans at disclosure), managing millions… |
Full article439 words · extracted from infosecurity-magazine.com · click to collapse
The Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI) and the Multi-State Information Sharing and Analysis Center (MS-ISAC) have issued a joint advisory, warning that the Medusa ransomware operation has impacted over 300 victims across critical infrastructure sectors.
Affected industries include healthcare, education, legal, insurance, technology and manufacturing.
A Growing Threat
Medusa, a ransomware-as-a-service (RaaS) variant first identified in June 2021, employs a double extortion model – encrypting victim data while also threatening to publicly release exfiltrated data if the ransom is not paid. Despite its name, Medusa ransomware is unrelated to MedusaLocker or the Medusa mobile malware variant.
The FBI’s investigation found that Medusa actors gain initial access through phishing campaigns and by exploiting unpatched software vulnerabilities, such as the ScreenConnect authentication bypass (CVE-2024-1709) and Fortinet EMS SQL injection flaw (CVE-2023-48788).
Once inside a network, they use legitimate administrative tools, including PowerShell and Windows Management Instrumentation (WMI), to evade detection, move laterally and deploy encryption payloads.
Increasing Sophistication
Medusa affiliates utilize various remote access tools such as AnyDesk, Atera and ConnectWise to infiltrate networks.
They also employ advanced techniques to evade detection, including obfuscated PowerShell scripts, disabling endpoint detection systems and leveraging reverse tunneling tools like Ligolo and Cloudflared.
A particularly alarming aspect of Medusa’s operations, CISA warned, is its extortion tactics.
Victims are pressured to pay within 48 hours via a Tor-based live chat or encrypted messaging platforms. If ignored, Medusa actors leak stolen data on their darknet site, offering it for sale before the countdown timer expires.
Reports suggest that even after a ransom is paid, victims may face additional extortion demands from different Medusa actors.
FBI and CISA Recommendations
The advisory strongly recommends that organizations implement mitigations to prevent falling victim to an attack, including:
- Keeping software updated and applying security patches
- Enforcing strong access controls and multi-factor authentication (MFA)
- Monitoring for unusual activity and restricting the use of remote desktop protocols (RDP)
- Implementing network segmentation to contain potential breaches
“This continues CISA’s long tradition of warning people about ransomware that spreads using social engineering, [which] does not suggest security awareness training as a primary way to defeat it,” noted Roger Grimes, a cybersecurity expert from KnowBe4.
“Social engineering is involved in 70-90% of all successful hacking attacks. [Ignoring this in their top recommendations] does a huge disservice [...] Hackers must be laughing.”
Regardless, the FBI and CISA urged organizations to report Medusa ransomware incidents to law enforcement and refrain from paying ransoms, as doing so risks encouraging further attacks.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/cisa-fbi-warn-medusa-ransomware/