🎯 Contexte
Le 18 août 2026, la CISA, le FBI et le Department of Health and Human Services (HHS) ont publié une mise à jour substantielle de l’advisory conjoint AA25-071A (#StopRansomware: Medusa Ransomware), initialement publié le 12 mars 2025. Cette analyse est produite par SafeBreach le 19 août 2026.
🦠 Présentation de Medusa
Medusa est une opération ransomware-as-a-service (RaaS) active depuis juin 2021, ayant impacté plus de 500 organisations d’infrastructure critique dans les secteurs médical, éducatif, juridique, assurance, technologie et manufacturing. Le groupe utilise un modèle de double (voire triple) extorsion et recrute des Initial Access Brokers (IABs) via des forums cybercriminels, rémunérés entre 100 $ et 1 million USD.
🆕 Nouveautés de la mise à jour d’août 2026
- Deux nouveaux CVE exploités :
CVE-2025-10035: désérialisation de données non fiables dans Fortra GoAnywhere (CWE-502)CVE-2026-1731: injection de commandes OS dans BeyondTrust (CWE-78)
- Interactsh utilisé pour vérifier l’exploitation hors-bande via des callbacks HTTP vers
oast[.]site,oast[.]pro,oast[.]fun - Weaponisation en moins de 24h après annonce publique d’un CVE, parfois jusqu’à une semaine avant la divulgation publique
- HHS ajouté comme co-signataire, reflétant la fréquence des victimes dans le secteur santé
🔧 TTPs clés (MITRE ATT&CK v19)
Initial Access :
- Phishing [T1566], exploitation d’applications publiques [T1190]
- CVEs : CVE-2024-1709 (ScreenConnect), CVE-2023-48788 (Fortinet EMS), CVE-2025-10035, CVE-2026-1731
Credential Access :
- Mimikatz LSASS dump [T1003.001], Minidump via
comsvcs.dll mimilib.dllenregistré comme SSP → logs dansC:\Windows\System32\kiwissp.log- Vol de
ntds.ditvia Volume Shadow Copy → forge de tickets Kerberos [T1558]
Defense Evasion :
- Rclone renommé (
lsp.exe,ngconf.txt) placé dans dossiers exclus de Defender [T1564.012] - Désactivation de Windows Defender via Group Policy Editor pendant l’exfiltration LSASS
- Commandes PowerShell base64 [T1027.013], suppression de l’historique PowerShell [T1070.003]
Lateral Movement :
- RDP [T1021.001], PsExec [T1569.002], outils RMM légitimes [T1219]
- PDQ Deploy pour pousser
gaze.exe; sur Linux :gaze.pyvia SFTP +nohup - Abus de commandes ESXi [T1675] pour forcer les mots de passe root
C2 :
- Nezha, MeshAgent, GSocket, Ligolo-ng, Cloudflared, shells bash/PHP
Exfiltration :
- Rclone vers serveurs C2 [T1567.002], Bandizip pour archivage,
rdpclip.exepour petits fichiers
Impact :
- Encrypteur
gaze.exe: AES-256, extension.medusa, suppression des shadow copies [T1490], arrêt des services [T1489]
📡 IOCs notables
- IP Nezha backdoor :
83.138.53[.]139 - IP/domaine exfiltration :
143.110.243[.]154/erp.ranasons[.]com - Domaines Interactsh :
oast[.]site,oast[.]pro,oast[.]fun - Fichiers :
gaze.exe,nezha-agent.exe,mimilib.dll,openrdp.bat,lsp.exe,ngconf.txt,Main_new.exe,file_save.php
📋 Type d’article
Il s’agit d’une analyse technique produite par SafeBreach à des fins de couverture défensive, mappant les TTPs Medusa à MITRE ATT&CK et documentant les nouvelles simulations d’attaque disponibles sur leur plateforme.
🧠 TTPs et IOCs détectés
Acteurs de menace
- Medusa (cybercriminal) —
TTP
- T1566 — Phishing (Initial Access)
- T1190 — Exploit Public-Facing Application (Initial Access)
- T1059.001 — Command and Scripting Interpreter: PowerShell (Execution)
- T1059.003 — Command and Scripting Interpreter: Windows Command Shell (Execution)
- T1047 — Windows Management Instrumentation (Execution)
- T1569.002 — System Services: Service Execution (Execution)
- T1072 — Software Deployment Tools (Execution)
- T1136.002 — Create Account: Domain Account (Persistence)
- T1484.001 — Domain Policy Modification: Group Policy Modification (Privilege Escalation)
- T1003.001 — OS Credential Dumping: LSASS Memory (Credential Access)
- T1558 — Steal or Forge Kerberos Tickets (Credential Access)
- T1027 — Obfuscated Files or Information (Defense Evasion)
- T1027.013 — Obfuscated Files or Information: Encrypted/Encoded File (Defense Evasion)
- T1070 — Indicator Removal (Defense Evasion)
- T1070.003 — Indicator Removal: Clear Command History (Defense Evasion)
- T1564.012 — Hide Artifacts: File/Path Exclusions (Defense Evasion)
- T1685 — Abuse Elevation Control Mechanism: Disable or Modify Tools (Defense Evasion)
- T1006 — Direct Volume Access (Defense Evasion)
- T1046 — Network Service Discovery (Discovery)
- T1083 — File and Directory Discovery (Discovery)
- T1082 — System Information Discovery (Discovery)
- T1033 — System Owner/User Discovery (Discovery)
- T1049 — System Network Connections Discovery (Discovery)
- T1069.002 — Permission Groups Discovery: Domain Groups (Discovery)
- T1135 — Network Share Discovery (Discovery)
- T1016 — System Network Configuration Discovery (Discovery)
- T1021.001 — Remote Services: Remote Desktop Protocol (Lateral Movement)
- T1219 — Remote Access Software (Command and Control)
- T1071.001 — Application Layer Protocol: Web Protocols (Command and Control)
- T1105 — Ingress Tool Transfer (Command and Control)
- T1675 — ESXi Administration Command (Lateral Movement)
- T1567.002 — Exfiltration Over Web Service: Exfiltration to Cloud Storage (Exfiltration)
- T1486 — Data Encrypted for Impact (Impact)
- T1489 — Service Stop (Impact)
- T1490 — Inhibit System Recovery (Impact)
- T1529 — System Shutdown/Reboot (Impact)
- T1657 — Financial Theft (Impact)
IOC
- IPv4 :
83.138.53.139— AbuseIPDB · VT · ThreatFox - IPv4 :
143.110.243.154— AbuseIPDB · VT · ThreatFox - Domaines :
erp.ranasons.com— VT · URLhaus · ThreatFox - Domaines :
oast.site— VT · URLhaus · ThreatFox - Domaines :
oast.pro— VT · URLhaus · ThreatFox - Domaines :
oast.fun— VT · URLhaus · ThreatFox - Domaines :
requestcatcher.com— VT · URLhaus · ThreatFox - Emails :
HHScyber@hhs.gov - CVEs :
CVE-2024-1709— NVD · CIRCL - CVEs :
CVE-2023-48788— NVD · CIRCL - CVEs :
CVE-2025-10035— NVD · CIRCL - CVEs :
CVE-2026-1731— NVD · CIRCL - Fichiers :
gaze.exe - Fichiers :
gaze.py - Fichiers :
nezha-agent.exe - Fichiers :
mimilib.dll - Fichiers :
j.exe - Fichiers :
def.exe - Fichiers :
Main_new.exe - Fichiers :
file_save.php - Fichiers :
openrdp.bat - Fichiers :
command.cmd - Fichiers :
RunFileCopy.cmd - Fichiers :
lsp.exe - Fichiers :
ngconf.txt - Fichiers :
powerfun.ps1 - Fichiers :
!!!READ_ME_MEDUSA!!!.txt - Chemins :
C:\Windows\System32\kiwissp.log
⚠️ À propos de ces IOC — ils sont extraits automatiquement de l’article original le 20 août 2026 et n’ont pas fait l’objet d’une vérification externe. Un indicateur peut avoir été réattribué depuis : une IP de C2 peut redevenir un service légitime, un domaine sinkholé peut changer de propriétaire. Aucune garantie d’exactitude ni d’actualité — contrôlez leur validité avant tout usage opérationnel, en particulier avant de les injecter dans une blocklist ou un SIEM.
Malware / Outils
- Medusa (ransomware)
- Mimikatz (tool)
- mimilib.dll (tool)
- Nezha (backdoor)
- MeshAgent (rat)
- GSocket (tool)
- Ligolo-ng (tool)
- Cloudflared (tool)
- Rclone (tool)
- Bandizip (tool)
- CrackMapExec (tool)
- Interactsh (tool)
- PsExec (tool)
- gaze.exe (ransomware)
- file_save.php (backdoor)
🟢 Indice de vérification factuelle : 75/100 (haute)
- ⬜ safebreach.com — source non référencée (0pts)
- ✅ 25481 chars — texte complet (fulltext extrait) (15pts)
- ✅ 28 IOCs (IPs/domaines/CVEs) (10pts)
- ✅ 5/5 IOCs confirmés (AbuseIPDB, ThreatFox, URLhaus, VirusTotal) (15pts)
- ✅ 37 TTPs MITRE identifiées (15pts)
- ✅ date extraite du HTML source (10pts)
- ✅ acteur(s) identifié(s) : Medusa (5pts)
- ✅ 4/4 CVE(s) confirmée(s) (CIRCL) (5pts)
IOCs confirmés externellement :
83.138.53.139(ip) → VT (9/91 détections)143.110.243.154(ip) → VT (5/91 détections)erp.ranasons.com(domain) → VT (5/91 détections)oast.site(domain) → VT (14/91 détections)oast.pro(domain) → VT (12/91 détections)
🔗 Source originale : https://www.safebreach.com/blog/safebreach-coverage-us-cert-aa25-071a-medusa-ransomware/