Medusa ransomware can disable antimalware tools, so it is on guard


  • Researchers detect Medusa ransomware operators that implement Smuol.sys
  • This driver imitates a legitimate driver of Falcon Falcon
  • Medusa actively addresses critical infrastructure organizations

Medusa ransomware operators are dedicated to outdated attacks to vulnerable driving attacks (Byod), without going through the protection, detection and response tools (EDR) (EDR) when installing the encryption.

The investigators of the elastic cybersecurity of the security laboratories noticed that the attacks begin as the threat actors drop a nameless charger, which displays two things at the objective final point: the vulnerable driver and the encryption.

Leave a Comment

Your email address will not be published. Required fields are marked *