Scientists Breach Cloud Storage of Medusa Ransomware Syndicate

The Medusa Ransomware Group suffered a major lapse in operational security (OPSEC) due to their use of Rclone—a prevalent data exfiltration tool—to deposit stolen data into the cloud storage service, put.io. This failure was rooted in a poorly configured Rclone setup, which included access tokens and credentials that were inadvertently exposed, granting unauthorized access to their cloud storage.

This security oversight allowed a third party to breach the Medusa group’s cloud storage, uncovering a significant cache of stolen data. Among the discovered files were sensitive records from victims such as the Kansas City Area Transportation Authority. This breach not only facilitated the recovery and deletion of critical files, mitigating potential damage to the victims, but also offered crucial insights into the Medusa group’s operations.

Rclone, known for managing cloud storage, was misused by an attacker who accessed the configuration file (conf.txt) located in C:\Windows\AppCompat. The attacker used put.io, an atypical cloud storage service, to exfiltrate data. This incident highlights the need for robust protection of cloud storage credentials and vigilance against unauthorized access.

The exposure of these security flaws underscores the necessity of meticulous configuration and continuous monitoring of cyber tools and services. The infiltration also provided valuable intelligence on the Medusa group’s methods and targets, stressing the importance of secure cloud storage practices and the risks of leaving sensitive data in unprotected areas.

In response, a Sigma rule has been developed to detect similar incidents involving the use of put.io for data exfiltration, aiming to bolster cybersecurity teams’ ability to identify and respond to such OPSEC failures.

The Medusa Ransomware Group’s OPSEC lapse reveals the critical need for stringent security protocols, especially when handling stolen data and utilizing cloud services. The Dark Atlas Squad exploited a security misconfiguration within the Medusa group’s operation, gaining temporary access to their cloud storage and analyzing the data being stolen. Despite Rclone’s compatibility with over 70 cloud providers, the Medusa group’s choice of the less common put.io service for data storage played a pivotal role in this security breach.

More Articles & Posts