WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Community Partnerships Joint Cybersecurity Advisory – #StopRansomware: MedusaLocker
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Directory
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Joint Cybersecurity Advisory – #StopRansomware: MedusaLocker

Author: Charles Egli

Created: Thursday, June 30, 2022 - 18:21

Categories: Cybersecurity

Today, the Cybersecurity and Infrastructure Security Agency (CISA), the FBI, and the Department of the Treasury published a joint Cybersecurity Advisory (CSA) to provide information on the MedusaLocker ransomware. As noted in the CSA, MedusaLocker threat actors rely predominantly on vulnerabilities in Remote Desktop Protocol (RDP) to access victims’ networks.

The CSA provides further technical details of MedusaLocker, to include noting threat actors also frequently use phishing and spam campaigns – directly attaching ransomware to the email – as initial intrusion vectors. The CSA provides an overview of how MedusaLocker operates, indicators of compromise, IP addresses, the MITRE ATT&ACK techniques used by the threat actors, and more. It includes a list of mitigation actions, resources, and reporting information. Among the mitigation actions, the CSA recommends organizations implement the following today: 1) prioritize remediating known exploited vulnerabilities; 2) train users to recognize and report phishing attempts; and 3) enable and enforce multi-factor authentication. To report an incident or request technical assistance, contact CISA at ci*************@******hs.gov or 888-282-0870 or the FBI through a local field office.

Related Resources

Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated May 1, 2026)

May 1, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness

Tip of the Week – April 30, 2026

Apr 30, 2026 in Cybersecurity, Security Preparedness

(TLP:CLEAR) Cyber Readiness Institute Joins WaterISAC as a Community Partner to Strengthen Cyber Readiness Across the Water Sector

Apr 30, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar