
Ransomware In Action: MedusaLocker ReadText34
Source: YouTube · John Hammond · published Sep 12, 2024 · 35:54
This video analyzes a real-world ransomware intrusion involving the ReadText variant (part of the Medusa Locker family), detailing its persistence mechanisms, destructive techniques, and the use of a "bring your own vulnerable driver" attack to bypass security controls 2:50-4:00, 30:13-30:15.
Key Takeaways:
• The attackers enabled Remote Desktop Protocol (RDP) via registry edits and established persistence using services and startup programs, including a malicious executable named winppx.exe 4:50-5:15.
• A key evasion tactic involved the truesight.sys kernel driver, a known "bring your own vulnerable driver" (BYOVD) used to terminate antivirus and EDR processes 11:50-12:20.
• Dynamic analysis revealed that winppx.exe dropped a batch script to disable driver integrity checks and staged a reverse proxy tool identified as RedLine for remote access 16:40-17:30, 22:00-22:20.
• Before encrypting files, the ransomware aggressively stopped database services and deleted Volume Shadow Copies and Windows Server backups to prevent data recovery 27:20-28:10, 28:50-29:10.
• Uniquely, the malware utilized the native Windows tool cipher.exe /w to wipe free disk space, rendering forensic recovery of deleted files or encryption keys impossible 30:13-30:15, 31:34-31:38.
The investigation underscores the sophistication of modern ransomware, which combines standard encryption with kernel-level evasion and anti-recovery tactics to maximize d
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
your company network has been penetrated all your important files have been encrypted this is the ransom note from a recent ransomware case that our security Operation Center got to dig into this is a real Ransom note includes a personal ID for the victim in the target of course I've redacted that here and the ransom note continues hey your files are safe only modified with RSA and AES encryption any attempt to restore your files with third party software will permanently corrupt it do not modify encrypted files do not rename encrypted files all the usual fearmongering you would expect from a ransom note and ransomware intrusion so I know what you might be thinking it's just the usual classic cookie cutter run-of-the-mill ransomware and that is a component but I think there are some other …