Deanonymizing Medusa Ransomware's Onion Site
It's not just the bad guys that can hack - our team recently uncovered the real IP address of the server hosting Medusa Locker's blog and negotiation site, by exploiting a vulnerability in their blog.
Medusa Locker primarily targets healthcare, education, and manufacturing sectors, with hundreds of reported attacks since its emergence in 2019. The group operates a Tor-based leak site to pressure victims, where they publish stolen data from organizations that refuse to pay.
๐งจ After uncovering a high severity vulnerability in Medusa Locker's ransomware blog - we successfully escalated and obtained the true IP address of their hidden host.

๐ Our analysis reveals that the server is located in Saint Petersburg, Russia, hosted by Selectel, one of the largest Russian providers, known for accepting payments in Bitcoin and Litecoin.
โณ ๐๐ฐ๐ญ๐ญ๐ฐ๐ธ ๐ฐ๐ถ๐ณ ๐ฑ๐ข๐จ๐ฆ ๐ต๐ฐ ๐ด๐ต๐ข๐บ ๐ถ๐ฑ๐ฅ๐ข๐ต๐ฆ๐ฅ ๐ง๐ฐ๐ณ ๐ฎ๐ฐ๐ณ๐ฆ ๐ฆ๐น๐ฑ๐ฐ๐ด๐ฆ๐ด, ๐ข๐ฏ๐ฅ ๐ต๐ฐ ๐ฃ๐ฆ ๐ต๐ฉ๐ฆ ๐ง๐ช๐ณ๐ด๐ต ๐ต๐ฐ ๐ฌ๐ฏ๐ฐ๐ธ ๐ข๐ฃ๐ฐ๐ถ๐ต ๐ฐ๐ถ๐ณ ๐ถ๐ฑ๐ค๐ฐ๐ฎ๐ช๐ฏ๐จ ๐ข๐ฅ๐ท๐ข๐ฏ๐ค๐ฆ๐ฅ ๐ฅ๐ข๐ณ๐ฌ ๐ธ๐ฆ๐ฃ ๐ช๐ฏ๐ต๐ฆ๐ญ๐ญ๐ช๐จ๐ฆ๐ฏ๐ค๐ฆ ๐ค๐ฐ๐ถ๐ณ๐ด๐ฆ!