Medusa

Winsage
December 17, 2024
The FBI has issued a warning about HiatusRAT malware that targets vulnerable web cameras and DVRs, particularly focusing on Chinese-branded devices lacking security updates. In March 2024, HiatusRAT actors conducted a scanning campaign against Internet of Things (IoT) devices in the US, Australia, Canada, New Zealand, and the UK. They exploit known vulnerabilities, including CVE-2017-7921, CVE-2018-9995, CVE-2020-25078, CVE-2021-33044, and CVE-2021-36260, as well as weak vendor-supplied passwords. Primary targets include Hikvision and Xiongmai devices with telnet access. Attackers use tools like Ingram and Medusa to exploit devices with exposed TCP ports such as 23, 26, 554, 2323, 567, 5523, 8080, 9530, and 56575. The FBI recommends limiting the use of affected devices and isolating them from broader networks. Previous attacks linked to HiatusRAT include targeting a Defense Department server and compromising businesses through DrayTek Vigor VPN routers. Lumen, a cybersecurity firm, noted that HiatusRAT is designed to deploy additional payloads and turn compromised systems into SOCKS5 proxies. The targeting strategy aligns with broader Chinese strategic interests as highlighted in the 2023 annual threat assessment by the Office of the Director of National Intelligence.
BetaBeacon
July 29, 2024
Forge of Empires by InnoGames is developing a new game called Heroes of History, which allows players to recruit historical figures to fight alongside them. The game includes both mythological and quirky historical figures like Abraham Lincoln and Marie Curie. Additionally, there are lists of the best mobile games of 2024 and most anticipated mobile games of the year.
Tech Optimizer
July 6, 2024
The Medusa Android trojan has made changes to evade detection, including requesting fewer permissions and adding new ones like Broadcasting SMS and Package Management. It is targeting people globally, with two different botnet groups operating in Turkey, Canada, the US, Italy, and France. The hackers are using new tactics, such as installing the malware through apps downloaded from untrusted sources.
Search