What Happened
Boston Scientific detected a cyberattack on August 25, 2026, that caused a global network outage, taking down manufacturing, order processing, and shipping systems [1][2]. The Marlborough, Massachusetts-based company disclosed the incident the following day through both a public newsroom statement and a Form 8-K filed with the SEC under Item 8.01 [2][3]. As of August 28, the company has not confirmed the attack type, the threat actor, the initial access vector, or whether any data was accessed or exfiltrated [2][3][10].
No ransomware group or other threat actor had claimed responsibility as of August 27 [2][3][11]. BleepingComputer confirmed it could not find any data extortion or ransomware threat actor claiming the breach [2]. SecurityWeek and The Register independently verified the same [3][5].
Boston Scientific operates in approximately 127 countries, employs roughly 59,000 people, runs 13 manufacturing facilities, and reported over $20.1 billion in annual revenue in 2025 [7][2]. Its devices are used to treat approximately 48 million patients per year [4]. The company's market capitalization stood at approximately $72 billion at the time of disclosure [6].
Operational Impact: Ireland and Beyond
The disruption hit immediately. On August 25, approximately 7,000 employees across Boston Scientific's three Irish plants were sent home [9]. Staff at the Cork Model Farm Road plant were reportedly sent home with full pay [9]. An internal staff message confirmed: "We are currently experiencing a global outage affecting network communications across our Ireland sites and other locations worldwide" [9].
By August 28, the Cork campus had cancelled all Friday shifts. Staff at the Model Farm Road plant were told: "Network issues continue. All shifts scheduled to start tomorrow, up to and including 6.30pm, are not operating" [8]. Employees across all three Irish plants reported contradictory staffing announcements, and trade union Siptu was asked to intervene on behalf of workers seeking clarity on work arrangements [8].
Boston Scientific has maintained operations in Ireland since 1994, with sites in Cork, Galway, and Clonmel [8].
Boston Scientific's stock declined in trading on August 26, with reports indicating a drop of between 3.5% and 4.5% depending on the trading window [6].
Financial Projections
Piper Sandler analysts, after speaking with company management on August 27, estimated that Boston Scientific may be able to resume shipping all products in less than three weeks [6][12]. Piper Sandler analyst Matt O'Brien wrote: "We believe BSX may be able to return to shipping all of its products in less than three weeks" [6].
Evercore ISI analyst Vijay Kumar projected a roughly 600 to 700 basis-point impact on third-quarter revenue, using the same recovery window [12]. Both firms used the Stryker recovery timeline (approximately three weeks to full restoration after its March 2026 attack) as a baseline [12].
What Boston Scientific Has Confirmed
Boston Scientific's incident page, updated August 27, states [1]:
- The cyberattack "continues to affect certain information technology systems."
- The company "remain[s] in a network outage with disruption to our operations."
- Affected functions include "the ability to manufacture products, as well as process and ship customer orders."
- "The timeline for a full restoration is not yet known."
On implanted devices specifically: "Our investigation to date demonstrates no impact to implantable cardiac rhythm management (CRM) device function. It also doesn't impact the device's ability to transmit data, or healthcare professionals' ability to access remote patient management" [1]. The company continues to "investigate potential impact to patients' implanted devices or to devices that connect to networks across our product portfolio" [1].
The SEC filing states: "The Company's investigation of the cybersecurity incident is ongoing, and the full scope, nature and impacts, including operational and financial impacts, of the incident are not yet known" [3]. Boston Scientific has not yet determined whether the incident is "reasonably likely" to have a material impact [7][13].
Boston Scientific spokesperson Chanel Hastings shared the company's public statement but would not comment on whether patients are affected, what steps patients should take, or the nature of the incident [4].
What Has Not Been Confirmed
The company has disclosed none of the following: attack type (ransomware, wiper, data theft, or otherwise), initial access vector, whether data was accessed or exfiltrated, whether a ransom demand was received, and whether manufacturing execution systems were directly compromised [2][3][4][10]. No indicators of compromise have been publicly released [10].
Devices and Product Lines Affected by the Supply Chain Halt
Boston Scientific's manufacturing and shipping shutdown affects its full product portfolio. The company manufactures devices across multiple regulated therapeutic categories [7]. A hospital cannot substitute these products on short notice [12]. Based on the company's public product disclosures and reporting on the incident, the following device categories face delayed delivery:
Cardiac Rhythm Management (CRM):
- Pacemakers (implantable pulse generators) [2][7]
- Implantable cardioverter-defibrillators (ICDs) [2][4]
- Cardiac resynchronization therapy devices (CRT-D, CRT-P) [7]
Electrophysiology and Structural Heart:
- WATCHMAN left atrial appendage occlusion system (stroke risk reduction) [12]
- FARAWAVE pulsed-field ablation catheter [12]
- Cardiac ablation systems [7]
Coronary and Vascular:
- Coronary stents [2][3]
- Vascular surgery devices [7]
- Interventional radiology products [7]
Neuromodulation:
- Spinal cord stimulators [12]
- Deep-brain stimulators [12]
Other Surgical and Diagnostic:
- Endoscopy devices [2][7]
- Pulmonology devices [7]
- Urology and pelvic health devices [7]
- Neurological surgery devices [7]
Boston Scientific stated it is "working to maintain continuity of supply" and that "patients and physicians are at the center of our recovery effort" [1].
Operational Pattern Assessment
Secureblink's analysis noted that the pattern Boston Scientific describes, specifically the simultaneous network outage, loss of order-processing and shipping across multiple countries, phased recovery, and precautionary work-from-home directive, is "consistent with an enterprise ransomware or network-wide intrusion rather than a narrow, single-application compromise" [10]. Companies commonly take large segments of infrastructure offline to contain encryption in progress or prevent lateral movement while scoping an intrusion [10].
The absence of a public claim does not rule out ransomware. Extortion groups typically name victims only after negotiations break down, which can take days to weeks after the initial intrusion [11].
Boston Scientific relies largely on Microsoft and Amazon Web Services for its corporate infrastructure, according to reporting based on public internet records [4].
The 2026 Medtech Attack Wave
Boston Scientific is at least the ninth major medtech company to disclose a cyberattack in 2026 [12][17]. The sector has faced an unprecedented concentration of attacks:
| Company | Timing | Details |
|---|---|---|
| UFP Technologies | January 2026 | SEC-disclosed cyberattack and data breach [15] |
| Stryker | March 2026 | The group Handala, assessed to be Iran-linked, reportedly compromised a Microsoft Intune admin account, triggering a mass wipe across systems in 79 countries; approximately three-week recovery [12][14][17] |
| Intuitive Surgical | March 2026 | Phishing incident compromising employee and customer data [17] |
| Medtronic | April 2026 | ShinyHunters claimed responsibility; 3.8 million individuals notified; data stolen reportedly included names, SSNs, health information [15] |
| West Pharmaceutical Services | May 2026 | Ransomware attack disclosed via SEC 8-K [11] |
| AdaptHealth | June 2026 | Cyberattack disclosed [13][17] |
| Abbott Laboratories | July 2026 | Cyberattack disclosed [17] |
| Cook Medical / Baylor Genetics | August 2026 | Both disclosed cyberattacks; Baylor Genetics breach reportedly included patient test results, SSNs, and financial data [17] |
| Boston Scientific | August 25, 2026 | Ongoing [1] |
Named threat actors targeting the medtech sector in 2026 include the group Handala (assessed to be Iran-linked), and the data theft and extortion groups ShinyHunters and FulcrumSec [16][17]. Health-ISAC issued a cybersecurity alert about ShinyHunters activity targeting healthcare, as reported by HIPAA Journal [16].
Dray Agha, senior manager of security operations at Huntress, commented: "The attack on Boston Scientific demonstrates that cyber incidents in the medtech sector extend far beyond IT and actively threaten the global healthcare supply chain" [13].
Industry Survey Data on Impact
The RunSafe Security 2026 Medical Device Cybersecurity Index, surveying 551 healthcare professionals across the U.S., U.K., and Germany, found that one in four organizations experienced a medical device attack in the past year that disrupted patient care [18]. In 80% of those cases, the impact on patients was rated "moderate" or "significant," ranging from delayed imaging and postponed procedures to interruptions in critical care delivery [18].
A separate EY and KLAS Research survey of 100 healthcare executives (November 2025) found 72% reported moderate to severe financial effects from a cybersecurity incident in the past two years, and 60% cited clinical impacts including delayed treatments [18].
MITRE ATT&CK: Techniques Observed Across 2026 Medtech Attacks
No TTPs have been confirmed for the Boston Scientific incident specifically. The following techniques are drawn from confirmed 2026 medtech attacks and the CISA/FBI/HHS Medusa ransomware advisory (last updated August 18, 2026) as relevant context:
| Technique ID | Name | Context |
|---|---|---|
| T1078 | Valid Accounts | Handala reportedly compromised Microsoft Intune admin account at Stryker [14] |
| T1485 | Data Destruction | Handala mass device wipe via Intune at Stryker [14] |
| T1567 | Exfiltration Over Web Service | ShinyHunters data exfiltration from Medtronic [15] |
| T1566 | Phishing | Intuitive Surgical phishing incident [17] |
| T1486 | Data Encrypted for Impact | Medusa ransomware encryptor deployment [20] |
| T1190 | Exploit Public-Facing Application | Medusa initial access technique [20] |
| T1219 | Remote Access Software | Medusa use of SimpleHelp, MeshAgent, BeyondTrust [20] |
| T1003.001 | OS Credential Dumping: LSASS Memory | Medusa use of mimilib.dll [20] |
| T1490 | Inhibit System Recovery | Medusa deletion of shadow copies [20] |
| T1489 | Service Stop | Medusa disabling security services [20] |
| T1036.005 | Masquerading: Match Legitimate Name or Location | Medusa renaming rclone.exe to lsp.exe [20] |
| T1567.002 | Exfiltration to Cloud Storage | Medusa use of rclone for exfiltration [20] |
IOC Table: Medusa Ransomware (CISA Advisory AA25-071A, Updated August 18, 2026)
These IOCs are from the joint CISA/FBI/HHS Medusa advisory [20], not from the Boston Scientific incident directly. They are included as relevant context given the healthcare sector targeting and the unconfirmed nature of the Boston Scientific attack type.
| Type | Value | Context |
|---|---|---|
| IP | 83.138.53.139 |
Nezha backdoor C2 server [20] |
| IP | 143.244.47.89 |
PHP web shell access via Mullvad VPN [20] |
| IP | 167.88.166.173 |
Ligolo proxy [20] |
| IP | 143.110.243.154 |
Exfiltration (erp.ranasons.com) [20] |
| IP | 45.61.150.94 |
SimpleHelp agent download server [20] |
| IP | 94.156.67.145 |
Backdoor C2 [20] |
| IP | 185.135.86.185 |
SimpleHelp remote access session [20] |
| Domain | erp.ranasons.com |
Exfiltration domain [20] |
| Domain | domains-oast.site |
Interactsh exploitation verification [20] |
| Domain | oast.pro |
Interactsh exploitation verification [20] |
| Domain | 3324.requestcatcher.com |
Ligolo and curl exfiltration [20] |
| Filename | gaze.exe |
Medusa ransomware encryptor (Windows) [20] |
| Filename | gaze.py |
Medusa ransomware encryptor (Linux) [20] |
| Filename | file_save.php |
PHP web shell [20] |
| Filename | nezha-agent.exe |
Nezha backdoor agent [20] |
| Filename | mimilib.dll |
Mimikatz credential theft component [20] |
| Filename | lsp.exe |
Renamed rclone.exe for exfiltration [20] |
| Filename | openrdp.bat |
Batch script enabling inbound RDP [20] |
| Filename | removesophos.bat |
Batch script removing Sophos [20] |
| Filename | def.exe |
Rootkit [20] |
| Filename | schost.exe |
Backdoor connecting to 94.156.67.145:11601 [20] |
Detection and Hunting
With no confirmed TTPs for the Boston Scientific incident, defenders should focus on the known 2026 medtech attack patterns and the updated Medusa advisory.
Network monitoring:
- Alert on connections to Medusa-associated IPs and domains listed in the IOC table above. Cross-reference DNS logs for
erp.ranasons.com,domains-oast.site,oast.pro, and3324.requestcatcher.com[20]. - Monitor for SimpleHelp, MeshAgent, or BeyondTrust sessions originating from VPN exit nodes (ExpressVPN, Mullvad) to internal hosts [20].
Endpoint detection:
- Hunt for the Medusa filenames:
gaze.exe,gaze.py,nezha-agent.exe,mimilib.dll,lsp.exe,schost.exe,def.exe[20]. - Watch for renamed
rclone.exeinstances andrclone.conffiles with obfuscated names (e.g.,lsp.exe,ngconf.txt) [20]. - Alert on batch script execution via PsExec:
openrdp.bat,removesophos.bat,uninstallSophos.bat,duooff.bat,newuser.bat[20].
Microsoft Intune / device management:
- Given the Stryker precedent (Handala reportedly abusing an Intune admin account to mass-wipe devices [14]), audit all Intune global administrator accounts for MFA enforcement, conditional access policies, and recent sign-in anomalies.
- Monitor for bulk device wipe or retire commands in Intune audit logs.
Sigma rule: Medusa batch script execution via PsExec
title: Medusa Ransomware Batch Script Execution via PsExec
id: a3f1e7b2-9c4d-4e8a-b5f6-1d2e3f4a5b6c
status: experimental
author: RedSheepSec
date: 2026/08/28
description: Detects execution of batch scripts associated with Medusa ransomware deployment via PsExec
logsource:
category: process_creation
product: windows
detection:
selection:
ParentImage|endswith: '\PsExec.exe'
Image|endswith: '\cmd.exe'
CommandLine|contains:
- 'openrdp.bat'
- 'removesophos.bat'
- 'uninstallSophos.bat'
- 'coba.bat'
- 'StopAllProcess.bat'
- 'zam.bat'
- 'duooff.bat'
- 'newuser.bat'
condition: selection
falsepositives:
- Legitimate administrative batch scripts executed via PsExec
level: high
references:
- https://www.ic3.gov/CSA/2026/260818.pdf
tags:
- attack.execution
- attack.t1569.002
Red Sheep Assessment
Confidence: Moderate
The operational signature of this incident, specifically the simultaneous global network outage, loss of manufacturing and order systems across multiple countries, phased recovery, and defensive isolation of infrastructure, is consistent with either a ransomware deployment or a destructive wiper attack. The company's careful SEC language ("has not yet determined whether the incident is reasonably likely to have a material impact") suggests the damage assessment is still in early stages and the outcome could go either way.
The three-week recovery estimate from Piper Sandler, benchmarked against Stryker, is plausible but optimistic. Stryker's attack involved a known mechanism (Intune admin account compromise and mass wipe), which simplified scoping. Boston Scientific has not confirmed the attack type at all, which could mean the incident is more complex to scope and remediate.
The absence of a public claim from any threat group as of day three is not meaningful in either direction. Ransomware operators commonly wait days to weeks before naming victims publicly, typically to preserve negotiating leverage [11].
Three scenarios are worth considering:
1. Ransomware with active negotiation. The most common explanation for the observed operational pattern. The company's refusal to characterize the attack type, combined with full manufacturing shutdown, fits a scenario where encryption occurred and the company is working through incident response and possibly negotiation.
2. Destructive wiper attack. Given the Handala precedent at Stryker, a politically motivated wiper cannot be dismissed. Boston Scientific's reliance on Microsoft infrastructure [4] could present a similar attack surface.
3. Supply chain compromise or third-party breach. Boston Scientific's cloud infrastructure dependencies create a third possibility, though nothing in the available reporting supports this over the first two scenarios.
The broader pattern is notable: nine medtech companies hit in eight months, with at least three named threat actor groups (Handala, ShinyHunters, FulcrumSec) and the CISA/FBI/HHS Medusa advisory specifically updated for healthcare targeting [16][20]. The medtech sector has moved from an occasional target to a primary target set.
Defender's Checklist
- ▢[ ] Audit device management admin accounts. Review all Microsoft Intune, SCCM, and MDM global administrator accounts for MFA enforcement and recent sign-in anomalies, given the Stryker/Handala Intune compromise precedent [14]. Specifically, review Entra ID sign-in logs for Intune admin roles for unfamiliar IP addresses, impossible travel, or token replay indicators.
- ▢[ ] Ingest Medusa IOCs into detection stack. Load IPs, domains, URLs, and filenames from the CISA AA25-071A advisory into SIEM, EDR, and firewall blocklists. Priority targets:
erp.ranasons.com,gaze.exe,nezha-agent.exe,mimilib.dll,lsp.exe[20]. - ▢[ ] Inventory Boston Scientific supply chain dependencies. Query ERP/procurement systems (e.g., Oracle, SAP) for open purchase orders with Boston Scientific. Cross-reference with surgical scheduling systems for procedures requiring BSX devices in the next 30 days. Contact BSX sales representatives for product-specific recovery timelines.
- ▢[ ] Hunt for renamed rclone instances. Search endpoints for
rclone.exerenamed to non-standard filenames (e.g.,lsp.exe) and any.conffiles with obfuscated names in user-writable directories [20]. - ▢[ ] Monitor for bulk device management commands. Set alerts in Intune/MDM audit logs for mass wipe, retire, or reset commands affecting more than 10 devices in a 24-hour window.
References
- Update on recent cybersecurity incident - Boston Scientific Newsroom
- Boston Scientific says cyberattack disrupted operations globally - BleepingComputer
- Cyberattack Causes Global Disruption at Boston Scientific - SecurityWeek
- Medical device maker Boston Scientific says a cyberattack is causing a 'global disruption' to its operations - TechCrunch
- Boston Scientific discloses 'global disruption' in ongoing cyberattack - The Register
- Medical device maker Boston Scientific is being hit by a cyberattack. The shares are falling - CNBC
- Boston Scientific Cyberattack Impacting Operations - HIPAA Journal
- Shifts cancelled at Boston Scientific in Cork after cyberattack - Irish Examiner
- Boston Scientific Confirms Cyberattack That Affected Network Communications, Disrupting Global Operations - TechNadu
- Boston Scientific Cyberattack Disrupts Global Operations - Secureblink
- Boston Scientific Cyberattack Halts Shipments: Weeks of Device Delays Threaten Hospital Supply - TechTimes
- Boston Scientific Cyberattack Stalls Cardiac Device Supply Chain for Hospitals - TechTimes
- Boston Scientific impacted by ongoing cyberattack - Medical Device Network / Yahoo Finance
- Stryker breach makes medical device cybersecurity a boardroom issue - Today's Medical Developments
- Medtronic Notifies 3.8M Individuals About April 2026 Cyberattack - HIPAA Journal
- AmGen Announces Cyberattack and Data Breach - HIPAA Journal
- Cyberattacks have plagued the medtech industry in 2026 - MedTech Dive
- Boston Scientific Cyberattack Halts Shipments (supply chain angle) - TechTimes
- Boston Scientific says cyberattack disrupted order processing, shipping - Cybersecurity Dive
- #StopRansomware: Medusa Ransomware (AA25-071A) - CISA/FBI/HHS Joint Advisory
Event Timeline
Timeline
Entity Relationships
Entity Graph (19 entities, 26 relationships)
Diamond Model
Diamond Model
Hunt Guide: Medusa Ransomware & 2026 Medtech Sector Cyberattack Wave — Boston Scientific Incident Context
Attribution: Rules adapted, ported, or quoted from a public source retain that source's author (e.g. SigmaHQ / Florian Roth, Elastic, Emerging Threats, Abuse.ch, or the cited vendor/researcher) and carry an attribution credit. Rules without a credit were authored in-house by RedSheepSec. If you reuse a rule, preserve its stated attribution.
Hypothesis: If Medusa ransomware operators, Handala, ShinyHunters, or related threat actors targeting the medtech/healthcare sector are active in our environment, we expect to observe connections to known Medusa C2 infrastructure, the presence of Medusa-associated filenames (gaze.exe, nezha-agent.exe, mimilib.dll, lsp.exe), renamed rclone instances for data exfiltration, batch scripts disabling security tools or enabling RDP executed via PsExec, abuse of remote access tools (SimpleHelp, MeshAgent), and anomalous bulk device management commands in Intune/SCCM audit logs, visible in Sysmon, Windows Security, network flow, DNS, EDR, and cloud audit log data sources.
Intelligence Summary: Boston Scientific detected a cyberattack on August 25, 2026, causing a global network outage that halted manufacturing, order processing, and shipping across its entire medical device portfolio. As of August 28, the company has not confirmed the attack type, threat actor, initial access vector, or whether data was exfiltrated; no threat actor has claimed responsibility. The operational pattern — simultaneous global outage, phased recovery, and infrastructure isolation — is assessed as consistent with enterprise ransomware or a network-wide destructive intrusion, and the incident occurs within a broader 2026 medtech attack wave involving at least nine major companies and named threat actors including Medusa (targeted by CISA Advisory AA25-071A updated August 18, 2026), Handala (assessed to be Iran-linked), ShinyHunters, and FulcrumSec.
Confidence: Moderate | Priority: Critical
Scope
- Networks: All enterprise network segments including corporate IT, clinical/biomedical device networks, manufacturing OT networks, cloud infrastructure (Azure/AWS), and VPN concentrators. Priority on segments with medical device management systems, ERP systems, and Intune/SCCM infrastructure.
- Timeframe: August 1, 2026 through present (30-day retrospective hunt). Extend to June 2026 for broader medtech campaign indicators. Medusa IOCs from the CISA advisory should be swept across all retained log data.
- Priority Systems: Microsoft Intune/Endpoint Manager admin consoles, Azure AD Global Administrator accounts, SCCM servers, medical device management systems, ERP/order processing systems (Oracle/SAP), manufacturing execution systems (MES), domain controllers, VPN concentrators, internet-facing web applications, and any systems hosting SimpleHelp/MeshAgent/BeyondTrust remote access agents.
MITRE ATT&CK Techniques
T1078 — Valid Accounts (Initial Access / Persistence) [P2]
Handala reportedly compromised a Microsoft Intune admin account at Stryker, enabling mass device wipes across 79 countries. Medusa operators also leverage valid accounts for initial access. Organizations using Microsoft Entra ID / Intune for device management should audit admin accounts for compromise indicators.
Splunk SPL:
index=cloud-azure sourcetype="azure:monitor:aad" OR sourcetype="mscs:azure:audit" ("RoleDefinition" OR "IntuneRole" OR "GlobalAdministrator" OR "Intune Administrator") ("Sign-in" OR "Add member to role" OR "Update device") | eval risk_score=case(like(properties.ipAddress,"10.%"),0,true(),50) | where risk_score>0 | stats count min(_time) as first_seen max(_time) as last_seen values(properties.ipAddress) as src_ips values(properties.userPrincipalName) as user by operationName | where count>3 | sort -count | table first_seen last_seen user operationName src_ips count
Elastic KQL:
event.dataset:"azure.auditlogs" AND (azure.auditlogs.properties.target_resources.display_name:"Intune" OR azure.auditlogs.operation_name:(*role* OR *wipe* OR *retire* OR *reset*)) AND NOT source.ip:(10.0.0.0/8 OR 172.16.0.0/12 OR 192.168.0.0/16)
Sigma Rule:
title: Suspicious Intune Admin Account Activity
id: b4e2f8a1-3c5d-4e9b-a6f7-2d3e4f5a6b7c
status: experimental
author: RedSheepSec
date: 2026/08/28
description: Detects suspicious sign-in or privilege escalation activity involving Intune or Global Administrator roles in Azure AD, relevant to the Handala/Stryker Intune compromise pattern
logsource:
product: azure
service: signinlogs
detection:
selection_role:
properties.appDisplayName|contains:
- 'Intune'
- 'Microsoft Endpoint Manager'
selection_action:
properties.status.errorCode: 0
filter_internal:
properties.ipAddress|startswith:
- '10.'
- '172.16.'
- '192.168.'
condition: selection_role and selection_action and not filter_internal
falsepositives:
- Legitimate Intune admin sign-ins from external networks
- VPN-connected administrators
level: high
references:
- https://www.todaysmedicaldevelopments.com/article/stryker-breach-makes-medical-device-cybersecurity-boardroom-issue/
tags:
- attack.initial_access
- attack.t1078
Tune by excluding known admin IP ranges and VPN egress points. Cross-reference with MFA challenge logs to identify sessions that bypassed MFA. Focus on Intune Global Administrator and Device Administrator roles.
T1485 — Data Destruction (Impact) [P2]
Handala reportedly used a compromised Intune admin account to issue mass device wipe commands at Stryker. Hunt for bulk wipe/retire/reset commands in device management audit logs that exceed normal administrative baselines.
Splunk SPL:
index=cloud-azure sourcetype="mscs:azure:audit" OR sourcetype="azure:monitor:aad" ("wipeDevice" OR "retireDevice" OR "resetPasscode" OR "remoteLock" OR "deleteDevice" OR "cleanWindowsDevice") | bin _time span=1h | stats count dc(properties.targetResources{}.displayName) as unique_devices values(properties.initiatedBy.user.userPrincipalName) as initiating_user by _time | where unique_devices > 10 | sort -unique_devices | table _time initiating_user unique_devices count
Elastic KQL:
event.dataset:"azure.auditlogs" AND azure.auditlogs.operation_name:(*wipe* OR *retire* OR *reset* OR *delete*Device*) | stats unique_count(azure.auditlogs.properties.target_resources.display_name) as device_count by azure.auditlogs.properties.initiated_by.user.user_principal_name
Sigma Rule:
title: Bulk Device Wipe Commands via Intune MDM
id: c5f3a9b2-4d6e-4f0a-b7c8-3e4f5a6b7c8d
status: experimental
author: RedSheepSec
date: 2026/08/28
description: Detects bulk device wipe, retire, or reset commands in Intune audit logs exceeding normal thresholds, based on the Handala/Stryker mass wipe attack pattern
logsource:
product: azure
service: auditlogs
detection:
selection:
operationName|contains:
- 'wipeDevice'
- 'retireDevice'
- 'resetPasscode'
- 'deleteDevice'
- 'cleanWindowsDevice'
condition: selection
timeframe: 1h
falsepositives:
- Legitimate bulk device retirement during hardware refresh
- MDM policy testing in non-production environments
level: critical
references:
- https://www.todaysmedicaldevelopments.com/article/stryker-breach-makes-medical-device-cybersecurity-boardroom-issue/
tags:
- attack.impact
- attack.t1485
Threshold of 10 devices in 1 hour should be tuned to local baseline. In most environments, legitimate bulk wipes are rare and coordinated with IT operations teams. Alert should trigger immediate investigation.
T1486 — Data Encrypted for Impact (Impact) [P1]
Medusa ransomware deploys encryptors (gaze.exe on Windows, gaze.py on Linux) for impact. The CISA AA25-071A advisory documents these as primary Medusa payloads. The Boston Scientific operational pattern is assessed as consistent with ransomware encryption.
Splunk SPL:
index=sysmon sourcetype="XmlWinEventLog" (EventCode=1 OR EventCode=11) ("gaze.exe" OR "gaze.py" OR ".medusa" OR "!!!READ_ME_MEDUSA!!!" OR "MEDUSA_README") | stats count min(_time) as first_seen max(_time) as last_seen values(Computer) as hosts values(Image) as processes values(TargetFilename) as files by User | table first_seen last_seen User hosts processes files count
Elastic KQL:
(process.name:("gaze.exe" OR "gaze.py") OR file.name:(*medusa* OR "!!!READ_ME_MEDUSA!!!*")) AND event.category:("process" OR "file")
Sigma Rule:
title: Medusa Ransomware Encryptor Execution
id: d6a4b0c3-5e7f-4a1b-c8d9-4f5a6b7c8d9e
status: experimental
author: RedSheepSec
date: 2026/08/28
description: Detects execution of Medusa ransomware encryptor binaries gaze.exe or gaze.py as documented in CISA Advisory AA25-071A
logsource:
category: process_creation
product: windows
detection:
selection:
Image|endswith:
- '\gaze.exe'
CommandLine|contains:
- 'gaze'
selection_python:
Image|endswith: '\python.exe'
CommandLine|contains: 'gaze.py'
condition: selection or selection_python
falsepositives:
- Extremely unlikely in enterprise environments
level: critical
references:
- https://www.ic3.gov/CSA/2026/260818.pdf
tags:
- attack.impact
- attack.t1486
Any match is a high-confidence indicator of Medusa ransomware. Immediately isolate the host and initiate IR procedures. Also hunt for ransom note filenames containing MEDUSA in Sysmon EventID 11 (FileCreate).
T1190 — Exploit Public-Facing Application (Initial Access) [P1]
Medusa ransomware operators use exploitation of public-facing applications as an initial access technique per CISA advisory. The domains domains-oast.site and oast.pro are used for Interactsh exploitation verification, indicating active vulnerability scanning and exploitation.
Splunk SPL:
index=corelight sourcetype=corelight_http ("oast.site" OR "oast.pro" OR "requestcatcher.com" OR "interactsh") | stats count min(_time) as first_seen max(_time) as last_seen values(id.orig_h) as src_ips values(id.resp_h) as dest_ips values(host) as hostnames by uri | sort -count | table first_seen last_seen src_ips dest_ips hostnames uri count
Elastic KQL:
destination.domain:(*oast.site OR *oast.pro OR *requestcatcher.com) OR url.domain:(*oast.site OR *oast.pro OR *requestcatcher.com)
Any connection to oast.site, oast.pro, or requestcatcher.com from internal hosts likely indicates exploitation verification or data exfiltration testing. These are Interactsh/out-of-band testing domains commonly used by attackers to confirm RCE.
T1219 — Remote Access Software (Command and Control) [P2]
Medusa operators deploy SimpleHelp, MeshAgent, and BeyondTrust remote access tools for persistent access. Hunt for unauthorized RMM tool installations, particularly SimpleHelp agent downloads from known Medusa infrastructure (45.61.150.94).
Splunk SPL:
index=sysmon sourcetype="XmlWinEventLog" EventCode=1 (Image="*SimpleHelp*" OR Image="*MeshAgent*" OR Image="*meshagent*" OR CommandLine="*SimpleHelp*" OR CommandLine="*MeshAgent*" OR OriginalFileName="*SimpleHelp*" OR OriginalFileName="*MeshAgent*") | stats count min(_time) as first_seen max(_time) as last_seen values(Computer) as hosts values(User) as users values(ParentImage) as parent_processes by Image CommandLine | table first_seen last_seen hosts users Image CommandLine parent_processes count
Elastic KQL:
(process.name:(*SimpleHelp* OR *MeshAgent* OR *meshagent*) OR process.command_line:(*SimpleHelp* OR *MeshAgent*)) AND event.category:"process"
Sigma Rule:
title: Unauthorized Remote Access Tool - SimpleHelp or MeshAgent
id: e7b5c1d4-6f8a-4b2c-d9e0-5a6b7c8d9e0f
status: experimental
author: RedSheepSec
date: 2026/08/28
description: Detects execution of SimpleHelp or MeshAgent remote access tools commonly abused by Medusa ransomware operators per CISA AA25-071A
logsource:
category: process_creation
product: windows
detection:
selection:
Image|contains:
- 'SimpleHelp'
- 'MeshAgent'
- 'meshagent'
CommandLine|contains:
- 'SimpleHelp'
- 'MeshAgent'
condition: selection
falsepositives:
- Legitimate IT support tools if SimpleHelp or MeshAgent are authorized RMM solutions
level: high
references:
- https://www.ic3.gov/CSA/2026/260818.pdf
tags:
- attack.command_and_control
- attack.t1219
If SimpleHelp or MeshAgent are not authorized RMM tools in your environment, any detection is suspicious. Cross-reference with the SimpleHelp download server IP 45.61.150.94. Also hunt for BeyondTrust sessions from unexpected source IPs.
T1003.001 — OS Credential Dumping: LSASS Memory (Credential Access) [P1]
Medusa ransomware operators deploy mimilib.dll (a Mimikatz component) for credential theft by hooking into LSASS. Hunt for mimilib.dll on disk and suspicious LSASS access patterns.
Splunk SPL:
index=sysmon sourcetype="XmlWinEventLog" ((EventCode=7 ImageLoaded="*mimilib.dll*") OR (EventCode=11 TargetFilename="*mimilib.dll*") OR (EventCode=10 TargetImage="*lsass.exe" GrantedAccess IN ("0x1010","0x1038","0x1F0FFF","0x1F1FFF","0x143A"))) | stats count min(_time) as first_seen max(_time) as last_seen values(Computer) as hosts values(SourceImage) as source_processes values(Image) as images by EventCode | table first_seen last_seen EventCode hosts source_processes images count
Elastic KQL:
(file.name:"mimilib.dll" OR (event.code:"10" AND winlog.event_data.TargetImage:"*lsass.exe" AND winlog.event_data.GrantedAccess:("0x1010" OR "0x1038" OR "0x1F0FFF" OR "0x1F1FFF")))
Sigma Rule:
title: Mimilib.dll Loaded or Created on Disk
id: f8c6d2e5-7a9b-4c3d-e0f1-6b7c8d9e0f1a
status: experimental
author: RedSheepSec
date: 2026/08/28
description: Detects mimilib.dll (Mimikatz credential theft component) being loaded into a process or created on disk, associated with Medusa ransomware per CISA AA25-071A
logsource:
category: image_load
product: windows
detection:
selection:
ImageLoaded|endswith: '\mimilib.dll'
condition: selection
falsepositives:
- Extremely unlikely in production environments
level: critical
references:
- https://www.ic3.gov/CSA/2026/260818.pdf
tags:
- attack.credential_access
- attack.t1003.001
Any detection of mimilib.dll should be treated as a confirmed compromise indicator. Also monitor for sekurlsa and other Mimikatz module names in process command lines.
T1490 — Inhibit System Recovery (Impact) [P1]
Medusa ransomware deletes shadow copies to inhibit system recovery before encrypting data. Hunt for vssadmin, wmic, or bcdedit commands used to delete shadow copies or disable recovery.
Splunk SPL:
index=sysmon sourcetype="XmlWinEventLog" EventCode=1 (CommandLine="*vssadmin*delete*shadows*" OR CommandLine="*wmic*shadowcopy*delete*" OR CommandLine="*bcdedit*recoveryenabled*no*" OR CommandLine="*wbadmin*delete*catalog*") | stats count min(_time) as first_seen max(_time) as last_seen values(Computer) as hosts values(User) as users values(ParentImage) as parent by Image CommandLine | table first_seen last_seen hosts users Image CommandLine parent count
Elastic KQL:
process.command_line:(*vssadmin*delete*shadow* OR *wmic*shadowcopy*delete* OR *bcdedit*recoveryenabled*no* OR *wbadmin*delete*catalog*) AND event.category:"process"
Shadow copy deletion is a high-fidelity pre-encryption indicator. False positives are rare in enterprise environments. Immediately escalate any detection.
T1489 — Service Stop (Impact) [P1]
Medusa ransomware disables security services before encryption. Hunt for batch scripts (removesophos.bat, uninstallSophos.bat) and net stop / sc stop commands targeting security products.
Splunk SPL:
index=sysmon sourcetype="XmlWinEventLog" EventCode=1 ((CommandLine="*removesophos*" OR CommandLine="*uninstallSophos*" OR CommandLine="*duooff*" OR CommandLine="*StopAllProcess*") OR (Image="*\cmd.exe" CommandLine="*net stop*" (CommandLine="*sophos*" OR CommandLine="*defender*" OR CommandLine="*crowdstrike*" OR CommandLine="*symantec*" OR CommandLine="*mcafee*" OR CommandLine="*carbon*"))) | stats count min(_time) as first_seen max(_time) as last_seen values(Computer) as hosts values(User) as users by Image CommandLine ParentImage | table first_seen last_seen hosts users Image CommandLine ParentImage count
Elastic KQL:
(process.command_line:(*removesophos* OR *uninstallSophos* OR *duooff* OR *StopAllProcess*) OR (process.name:"cmd.exe" AND process.command_line:(*net*stop* AND (*sophos* OR *defender* OR *crowdstrike* OR *symantec*)))) AND event.category:"process"
Any attempt to stop security services outside of authorized maintenance windows is a critical indicator. Cross-reference with change management tickets.
T1036.005 — Masquerading: Match Legitimate Name or Location (Defense Evasion) [P1]
Medusa operators rename rclone.exe to lsp.exe for exfiltration. Hunt for rclone binaries with non-standard filenames and associated configuration files with obfuscated names (e.g., ngconf.txt).
Splunk SPL:
index=sysmon sourcetype="XmlWinEventLog" EventCode=1 ((OriginalFileName="rclone.exe" NOT Image="*\rclone.exe") OR (Image="*\lsp.exe" NOT OriginalFileName="lsp.exe") OR CommandLine="*rclone*" OR CommandLine="*ngconf.txt*") | stats count min(_time) as first_seen max(_time) as last_seen values(Computer) as hosts values(User) as users by Image OriginalFileName CommandLine | table first_seen last_seen hosts users Image OriginalFileName CommandLine count
Elastic KQL:
((process.pe.original_file_name:"rclone.exe" AND NOT process.name:"rclone.exe") OR (process.name:"lsp.exe" AND NOT process.pe.original_file_name:"lsp.exe") OR process.command_line:(*rclone* OR *ngconf.txt*)) AND event.category:"process"
Sigma Rule:
title: Renamed Rclone Binary Execution - Medusa Exfiltration
id: a1b2c3d4-8e9f-4a5b-c6d7-7e8f9a0b1c2d
status: experimental
author: RedSheepSec
date: 2026/08/28
description: Detects execution of rclone.exe renamed to a non-standard filename (e.g., lsp.exe) as used by Medusa ransomware for data exfiltration per CISA AA25-071A
logsource:
category: process_creation
product: windows
detection:
selection_renamed:
OriginalFileName: 'rclone.exe'
filter_legitimate:
Image|endswith: '\rclone.exe'
selection_lsp:
Image|endswith: '\lsp.exe'
filter_lsp_legit:
OriginalFileName: 'lsp.exe'
condition: (selection_renamed and not filter_legitimate) or (selection_lsp and not filter_lsp_legit)
falsepositives:
- Legitimate rclone renamed by IT automation (extremely rare in enterprise)
level: critical
references:
- https://www.ic3.gov/CSA/2026/260818.pdf
tags:
- attack.defense_evasion
- attack.t1036.005
Requires Sysmon with OriginalFileName logging (EventID 1 with hashing enabled). Any renamed rclone binary is a strong indicator of data staging for exfiltration.
T1567.002 — Exfiltration to Cloud Storage (Exfiltration) [P1]
Medusa uses rclone (often renamed to lsp.exe) to exfiltrate data to cloud storage, including the domain erp.ranasons.com (IP 143.110.243.154). Hunt for rclone network connections and DNS lookups for the exfiltration domain.
Splunk SPL:
index=corelight sourcetype=corelight_dns ("erp.ranasons.com" OR "ranasons.com" OR "3324.requestcatcher.com") | stats count min(_time) as first_seen max(_time) as last_seen values(id.orig_h) as src_ips values(answers) as resolved_ips by query | table first_seen last_seen src_ips query resolved_ips count
Elastic KQL:
dns.question.name:(*ranasons.com OR *requestcatcher.com) OR destination.domain:(*ranasons.com OR *requestcatcher.com)
Any DNS resolution of erp.ranasons.com or 3324.requestcatcher.com is a direct IOC match. Also monitor for large outbound data transfers to cloud storage providers from hosts running rclone or lsp.exe.
T1566 — Phishing (Initial Access) [P2]
Intuitive Surgical's March 2026 incident involved phishing that compromised employee and customer data. Medusa operators also use phishing for initial access. Hunt for phishing indicators in email and endpoint logs.
Splunk SPL:
index=sysmon sourcetype="XmlWinEventLog" EventCode=1 (ParentImage="*\OUTLOOK.EXE" OR ParentImage="*\WINWORD.EXE" OR ParentImage="*\EXCEL.EXE" OR ParentImage="*\POWERPNT.EXE") (Image="*\cmd.exe" OR Image="*\powershell.exe" OR Image="*\wscript.exe" OR Image="*\cscript.exe" OR Image="*\mshta.exe" OR Image="*\certutil.exe") | stats count min(_time) as first_seen max(_time) as last_seen values(Computer) as hosts values(User) as users by ParentImage Image CommandLine | table first_seen last_seen hosts users ParentImage Image CommandLine count
Elastic KQL:
process.parent.name:(OUTLOOK.EXE OR WINWORD.EXE OR EXCEL.EXE OR POWERPNT.EXE) AND process.name:(cmd.exe OR powershell.exe OR wscript.exe OR cscript.exe OR mshta.exe OR certutil.exe) AND event.category:"process"
This is a broad behavioral detection for Office application spawning suspicious child processes. Tune based on environment — some legitimate add-ins may trigger. Focus on healthcare/medtech-themed phishing lures.
T1567 — Exfiltration Over Web Service (Exfiltration) [P2]
ShinyHunters exfiltrated data from Medtronic reportedly including names, SSNs, and health information for 3.8 million individuals. Hunt for large outbound data transfers and connections to known exfiltration infrastructure.
Splunk SPL:
index=corelight sourcetype=corelight_conn id.resp_p IN (443, 80, 8443) orig_bytes>104857600 NOT id.resp_h IN ("10.0.0.0/8","172.16.0.0/12","192.168.0.0/16") | eval MB_sent=round(orig_bytes/1048576,2) | stats sum(MB_sent) as total_MB_sent count by id.orig_h id.resp_h id.resp_p | where total_MB_sent > 500 | sort -total_MB_sent | table id.orig_h id.resp_h id.resp_p total_MB_sent count
Elastic KQL:
network.bytes > 104857600 AND destination.port:(443 OR 80 OR 8443) AND NOT destination.ip:(10.0.0.0/8 OR 172.16.0.0/12 OR 192.168.0.0/16) AND event.dataset:"zeek.conn"
Threshold of 500MB total outbound to a single destination should be tuned to your environment. Legitimate cloud services (O365, AWS, backup) should be whitelisted. Focus on unusual destinations.
Indicators of Compromise
| Type | Value | Context |
|---|---|---|
| ip | 83.138.53.139 |
Nezha backdoor C2 server - Medusa ransomware (CISA Advisory AA25-071A) |
| ip | 143.244.47.89 |
PHP web shell access via Mullvad VPN - Medusa ransomware (CISA Advisory AA25-071A) |
| ip | 167.88.166.173 |
Ligolo proxy - Medusa ransomware (CISA Advisory AA25-071A) |
| ip | 143.110.243.154 |
Exfiltration server hosting erp.ranasons.com - Medusa ransomware (CISA Advisory AA25-071A) |
| ip | 45.61.150.94 |
SimpleHelp agent download server - Medusa ransomware (CISA Advisory AA25-071A) |
| ip | 94.156.67.145 |
Backdoor C2 (schost.exe connects to port 11601) - Medusa ransomware (CISA Advisory AA25-071A) |
| ip | 185.135.86.185 |
SimpleHelp remote access session - Medusa ransomware (CISA Advisory AA25-071A) |
| domain | erp.ranasons.com |
Exfiltration domain - Medusa ransomware (CISA Advisory AA25-071A) |
| domain | domains-oast.site |
Interactsh exploitation verification domain - Medusa ransomware (CISA Advisory AA25-071A) |
| domain | oast.pro |
Interactsh exploitation verification domain - Medusa ransomware (CISA Advisory AA25-071A) |
| domain | 3324.requestcatcher.com |
Ligolo and curl exfiltration domain - Medusa ransomware (CISA Advisory AA25-071A) |
| filename | gaze.exe |
Medusa ransomware encryptor (Windows) - CISA Advisory AA25-071A |
| filename | gaze.py |
Medusa ransomware encryptor (Linux) - CISA Advisory AA25-071A |
| filename | file_save.php |
PHP web shell - Medusa ransomware (CISA Advisory AA25-071A) |
| filename | nezha-agent.exe |
Nezha backdoor agent - Medusa ransomware (CISA Advisory AA25-071A) |
| filename | mimilib.dll |
Mimikatz credential theft component - Medusa ransomware (CISA Advisory AA25-071A) |
| filename | lsp.exe |
Renamed rclone.exe for exfiltration - Medusa ransomware (CISA Advisory AA25-071A) |
| filename | openrdp.bat |
Batch script enabling inbound RDP - Medusa ransomware (CISA Advisory AA25-071A) |
| filename | removesophos.bat |
Batch script removing Sophos security - Medusa ransomware (CISA Advisory AA25-071A) |
| filename | def.exe |
Rootkit - Medusa ransomware (CISA Advisory AA25-071A) |
| filename | schost.exe |
Backdoor connecting to 94.156.67.145:11601 - Medusa ransomware (CISA Advisory AA25-071A) |
IOC Sweep Queries (Splunk):
index=corelight (sourcetype=corelight_conn OR sourcetype=corelight_dns OR sourcetype=corelight_http OR sourcetype=corelight_ssl) ("83.138.53.139") | stats count min(_time) as first_seen max(_time) as last_seen values(id.orig_h) as src_ips values(id.resp_p) as dest_ports by sourcetype | table first_seen last_seen sourcetype src_ips dest_ports count
index=corelight (sourcetype=corelight_conn OR sourcetype=corelight_dns OR sourcetype=corelight_http OR sourcetype=corelight_ssl) ("143.244.47.89") | stats count min(_time) as first_seen max(_time) as last_seen values(id.orig_h) as src_ips values(id.resp_p) as dest_ports by sourcetype | table first_seen last_seen sourcetype src_ips dest_ports count
index=corelight (sourcetype=corelight_conn OR sourcetype=corelight_dns OR sourcetype=corelight_http OR sourcetype=corelight_ssl) ("167.88.166.173") | stats count min(_time) as first_seen max(_time) as last_seen values(id.orig_h) as src_ips values(id.resp_p) as dest_ports by sourcetype | table first_seen last_seen sourcetype src_ips dest_ports count
index=corelight (sourcetype=corelight_conn OR sourcetype=corelight_dns OR sourcetype=corelight_http OR sourcetype=corelight_ssl) ("143.110.243.154") | stats count min(_time) as first_seen max(_time) as last_seen values(id.orig_h) as src_ips values(id.resp_p) as dest_ports by sourcetype | table first_seen last_seen sourcetype src_ips dest_ports count
index=corelight (sourcetype=corelight_conn OR sourcetype=corelight_dns OR sourcetype=corelight_http OR sourcetype=corelight_ssl) ("45.61.150.94") | stats count min(_time) as first_seen max(_time) as last_seen values(id.orig_h) as src_ips values(id.resp_p) as dest_ports by sourcetype | table first_seen last_seen sourcetype src_ips dest_ports count
index=corelight (sourcetype=corelight_conn OR sourcetype=corelight_dns OR sourcetype=corelight_http OR sourcetype=corelight_ssl) ("94.156.67.145") | stats count min(_time) as first_seen max(_time) as last_seen values(id.orig_h) as src_ips values(id.resp_p) as dest_ports by sourcetype | table first_seen last_seen sourcetype src_ips dest_ports count
index=corelight (sourcetype=corelight_conn OR sourcetype=corelight_dns OR sourcetype=corelight_http OR sourcetype=corelight_ssl) ("185.135.86.185") | stats count min(_time) as first_seen max(_time) as last_seen values(id.orig_h) as src_ips values(id.resp_p) as dest_ports by sourcetype | table first_seen last_seen sourcetype src_ips dest_ports count
index=corelight sourcetype=corelight_dns "erp.ranasons.com" | stats count min(_time) as first_seen max(_time) as last_seen values(id.orig_h) as src_ips values(answers) as resolved_ips by query | table first_seen last_seen src_ips query resolved_ips count
index=corelight sourcetype=corelight_dns "*oast.site" | stats count min(_time) as first_seen max(_time) as last_seen values(id.orig_h) as src_ips values(answers) as resolved_ips by query | table first_seen last_seen src_ips query resolved_ips count
index=corelight sourcetype=corelight_dns "*oast.pro" | stats count min(_time) as first_seen max(_time) as last_seen values(id.orig_h) as src_ips values(answers) as resolved_ips by query | table first_seen last_seen src_ips query resolved_ips count
index=corelight sourcetype=corelight_dns "*requestcatcher.com" | stats count min(_time) as first_seen max(_time) as last_seen values(id.orig_h) as src_ips values(answers) as resolved_ips by query | table first_seen last_seen src_ips query resolved_ips count
index=sysmon sourcetype="XmlWinEventLog" ("gaze.exe") | stats count min(_time) as first_seen max(_time) as last_seen values(Computer) as hosts values(User) as users by EventCode Image TargetFilename | table first_seen last_seen EventCode hosts users Image TargetFilename count
index=linux-server ("gaze.py") | stats count min(_time) as first_seen max(_time) as last_seen values(host) as hosts by source sourcetype | table first_seen last_seen hosts source sourcetype count
index=sysmon sourcetype="XmlWinEventLog" ("file_save.php") | stats count min(_time) as first_seen max(_time) as last_seen values(Computer) as hosts by EventCode Image TargetFilename | table first_seen last_seen EventCode hosts Image TargetFilename count
index=sysmon sourcetype="XmlWinEventLog" ("nezha-agent.exe" OR "nezha-agent") | stats count min(_time) as first_seen max(_time) as last_seen values(Computer) as hosts values(User) as users by EventCode Image CommandLine | table first_seen last_seen EventCode hosts users Image CommandLine count
index=sysmon sourcetype="XmlWinEventLog" ("mimilib.dll") | stats count min(_time) as first_seen max(_time) as last_seen values(Computer) as hosts by EventCode Image ImageLoaded TargetFilename | table first_seen last_seen EventCode hosts Image ImageLoaded TargetFilename count
index=sysmon sourcetype="XmlWinEventLog" EventCode=1 Image="*\lsp.exe" | stats count min(_time) as first_seen max(_time) as last_seen values(Computer) as hosts values(User) as users by Image OriginalFileName CommandLine | table first_seen last_seen hosts users Image OriginalFileName CommandLine count
index=sysmon sourcetype="XmlWinEventLog" EventCode=1 ("openrdp.bat") | stats count min(_time) as first_seen max(_time) as last_seen values(Computer) as hosts values(User) as users by Image CommandLine ParentImage | table first_seen last_seen hosts users Image CommandLine ParentImage count
index=sysmon sourcetype="XmlWinEventLog" EventCode=1 ("removesophos.bat") | stats count min(_time) as first_seen max(_time) as last_seen values(Computer) as hosts values(User) as users by Image CommandLine ParentImage | table first_seen last_seen hosts users Image CommandLine ParentImage count
index=sysmon sourcetype="XmlWinEventLog" EventCode=1 Image="*\def.exe" | stats count min(_time) as first_seen max(_time) as last_seen values(Computer) as hosts values(User) as users by Image OriginalFileName CommandLine ParentImage | table first_seen last_seen hosts users Image OriginalFileName CommandLine ParentImage count
index=sysmon sourcetype="XmlWinEventLog" (EventCode=1 Image="*\schost.exe") OR (EventCode=3 Image="*\schost.exe") | stats count min(_time) as first_seen max(_time) as last_seen values(Computer) as hosts values(DestinationIp) as dest_ips values(DestinationPort) as dest_ports by Image CommandLine | table first_seen last_seen hosts Image CommandLine dest_ips dest_ports count
YARA Rules
Medusa_Ransomware_Indicators — Detects Medusa ransomware components including encryptor binaries, backdoor agents, and associated tools based on CISA Advisory AA25-071A IOCs
rule Medusa_Ransomware_Indicators {
meta:
description = "Detects Medusa ransomware components and associated tools per CISA AA25-071A"
author = "RedSheepSec"
date = "2026-08-28"
reference = "https://www.ic3.gov/CSA/2026/260818.pdf"
threat = "Medusa Ransomware"
strings:
$encryptor_win = "gaze.exe" ascii wide nocase
$encryptor_lin = "gaze.py" ascii wide nocase
$nezha = "nezha-agent.exe" ascii wide nocase
$nezha2 = "nezha-agent" ascii wide nocase
$mimilib = "mimilib.dll" ascii wide nocase
$webshell = "file_save.php" ascii wide nocase
$rootkit = "def.exe" ascii wide nocase
$backdoor = "schost.exe" ascii wide nocase
$ransom_note1 = "!!!READ_ME_MEDUSA!!!" ascii wide
$ransom_note2 = "MEDUSA_README" ascii wide
$c2_ip1 = "83.138.53.139" ascii wide
$c2_ip2 = "94.156.67.145" ascii wide
$exfil_domain = "erp.ranasons.com" ascii wide
$bat_rdp = "openrdp.bat" ascii wide nocase
$bat_sophos = "removesophos.bat" ascii wide nocase
$bat_sophos2 = "uninstallSophos.bat" ascii wide nocase
$bat_duo = "duooff.bat" ascii wide nocase
$bat_user = "newuser.bat" ascii wide nocase
$lsp = "lsp.exe" ascii wide nocase
condition:
any of them
}
Medusa_Renamed_Rclone — Detects rclone binary potentially renamed for data exfiltration, a technique used by Medusa ransomware operators
rule Medusa_Renamed_Rclone {
meta:
description = "Detects rclone binary indicators in non-rclone named executables, associated with Medusa exfiltration"
author = "RedSheepSec"
date = "2026-08-28"
reference = "https://www.ic3.gov/CSA/2026/260818.pdf"
threat = "Medusa Ransomware Exfiltration"
strings:
$rclone_str1 = "rclone" ascii wide
$rclone_str2 = "rclone.org" ascii wide
$rclone_str3 = "rclone/rclone" ascii wide
$config1 = "ngconf.txt" ascii wide nocase
$config2 = "rclone.conf" ascii wide nocase
$pe_header = { 4D 5A }
condition:
$pe_header at 0 and (2 of ($rclone_str*) or any of ($config*))
}
Suricata Rules
SID 2026001 — Detects DNS query for Medusa ransomware exfiltration domain erp.ranasons.com
alert dns $HOME_NET any -> any any (msg:"MEDUSA Ransomware - DNS Query for Exfiltration Domain erp.ranasons.com"; dns.query; content:"erp.ranasons.com"; nocase; classtype:trojan-activity; sid:2026001; rev:1; metadata:created_at 2026_08_28, updated_at 2026_08_28; reference:url,www.ic3.gov/CSA/2026/260818.pdf;)
SID 2026002 — Detects DNS query for Interactsh exploitation verification domain oast.site (Medusa)
alert dns $HOME_NET any -> any any (msg:"MEDUSA Ransomware - DNS Query for Interactsh Domain oast.site"; dns.query; content:"oast.site"; nocase; classtype:trojan-activity; sid:2026002; rev:1; metadata:created_at 2026_08_28, updated_at 2026_08_28; reference:url,www.ic3.gov/CSA/2026/260818.pdf;)
SID 2026003 — Detects DNS query for Interactsh exploitation verification domain oast.pro (Medusa)
alert dns $HOME_NET any -> any any (msg:"MEDUSA Ransomware - DNS Query for Interactsh Domain oast.pro"; dns.query; content:"oast.pro"; nocase; classtype:trojan-activity; sid:2026003; rev:1; metadata:created_at 2026_08_28, updated_at 2026_08_28; reference:url,www.ic3.gov/CSA/2026/260818.pdf;)
SID 2026004 — Detects DNS query for requestcatcher.com exfiltration domain (Medusa/Ligolo)
alert dns $HOME_NET any -> any any (msg:"MEDUSA Ransomware - DNS Query for requestcatcher.com Exfiltration"; dns.query; content:"requestcatcher.com"; nocase; classtype:trojan-activity; sid:2026004; rev:1; metadata:created_at 2026_08_28, updated_at 2026_08_28; reference:url,www.ic3.gov/CSA/2026/260818.pdf;)
SID 2026005 — Detects outbound connection to Medusa Nezha backdoor C2 at 83.138.53.139
alert ip $HOME_NET any -> 83.138.53.139 any (msg:"MEDUSA Ransomware - Outbound Connection to Nezha C2 83.138.53.139"; classtype:trojan-activity; sid:2026005; rev:1; metadata:created_at 2026_08_28, updated_at 2026_08_28; reference:url,www.ic3.gov/CSA/2026/260818.pdf;)
SID 2026006 — Detects outbound connection to Medusa backdoor C2 at 94.156.67.145
alert ip $HOME_NET any -> 94.156.67.145 any (msg:"MEDUSA Ransomware - Outbound Connection to Backdoor C2 94.156.67.145"; classtype:trojan-activity; sid:2026006; rev:1; metadata:created_at 2026_08_28, updated_at 2026_08_28; reference:url,www.ic3.gov/CSA/2026/260818.pdf;)
SID 2026007 — Detects outbound connection to Medusa SimpleHelp download server at 45.61.150.94
alert ip $HOME_NET any -> 45.61.150.94 any (msg:"MEDUSA Ransomware - Outbound Connection to SimpleHelp Server 45.61.150.94"; classtype:trojan-activity; sid:2026007; rev:1; metadata:created_at 2026_08_28, updated_at 2026_08_28; reference:url,www.ic3.gov/CSA/2026/260818.pdf;)
SID 2026008 — Detects outbound connection to Medusa exfiltration server at 143.110.243.154
alert ip $HOME_NET any -> 143.110.243.154 any (msg:"MEDUSA Ransomware - Outbound Connection to Exfiltration Server 143.110.243.154"; classtype:trojan-activity; sid:2026008; rev:1; metadata:created_at 2026_08_28, updated_at 2026_08_28; reference:url,www.ic3.gov/CSA/2026/260818.pdf;)
SID 2026009 — Detects outbound connection to Medusa web shell access IP 143.244.47.89
alert ip $HOME_NET any -> 143.244.47.89 any (msg:"MEDUSA Ransomware - Outbound Connection to Web Shell IP 143.244.47.89"; classtype:trojan-activity; sid:2026009; rev:1; metadata:created_at 2026_08_28, updated_at 2026_08_28; reference:url,www.ic3.gov/CSA/2026/260818.pdf;)
SID 2026010 — Detects outbound connection to Medusa Ligolo proxy at 167.88.166.173
alert ip $HOME_NET any -> 167.88.166.173 any (msg:"MEDUSA Ransomware - Outbound Connection to Ligolo Proxy 167.88.166.173"; classtype:trojan-activity; sid:2026010; rev:1; metadata:created_at 2026_08_28, updated_at 2026_08_28; reference:url,www.ic3.gov/CSA/2026/260818.pdf;)
SID 2026011 — Detects outbound connection to Medusa SimpleHelp remote access at 185.135.86.185
alert ip $HOME_NET any -> 185.135.86.185 any (msg:"MEDUSA Ransomware - Outbound Connection to SimpleHelp 185.135.86.185"; classtype:trojan-activity; sid:2026011; rev:1; metadata:created_at 2026_08_28, updated_at 2026_08_28; reference:url,www.ic3.gov/CSA/2026/260818.pdf;)
SID 2026012 — Detects schost.exe backdoor connecting to C2 on port 11601 (Medusa)
alert tcp $HOME_NET any -> any 11601 (msg:"MEDUSA Ransomware - schost.exe Backdoor C2 Port 11601"; flow:established,to_server; classtype:trojan-activity; sid:2026012; rev:1; metadata:created_at 2026_08_28, updated_at 2026_08_28; reference:url,www.ic3.gov/CSA/2026/260818.pdf;)
Data Source Requirements
| Source | Required For | Notes |
|---|---|---|
| Sysmon (EventID 1 - Process Creation) | T1486, T1219, T1003.001, T1490, T1489, T1036.005, T1566 | Requires Sysmon with process creation logging including command line and OriginalFileName. Ensure Sysmon config captures hash values and parent process information. Available in index=sysmon. |
| Sysmon (EventID 3 - Network Connection) | T1219, T1567.002 | Network connection logging from Sysmon. Ensure config captures outbound connections. Available in index=sysmon. |
| Sysmon (EventID 7 - Image Load) | T1003.001 | Image load logging needed to detect mimilib.dll being loaded. Available in index=sysmon. |
| Sysmon (EventID 10 - Process Access) | T1003.001 | Process access logging needed to detect LSASS memory access. Available in index=sysmon. |
| Sysmon (EventID 11 - File Create) | T1486, T1003.001 | File creation logging for detecting Medusa ransom notes and dropped tools. Available in index=sysmon. |
| Zeek/Corelight DNS Logs | T1567.002, T1190 | DNS query logging for IOC domain resolution detection. Available in index=corelight sourcetype=corelight_dns. |
| Zeek/Corelight Connection Logs | T1567, T1567.002 | Connection metadata for detecting large outbound transfers and C2 connections. Available in index=corelight sourcetype=corelight_conn. |
| Zeek/Corelight HTTP Logs | T1190, T1567.002 | HTTP request logging for detecting exploitation verification callbacks. Available in index=corelight sourcetype=corelight_http. |
| Azure AD / Entra ID Sign-In Logs | T1078, T1485 | Azure AD sign-in and audit logs for detecting Intune admin compromise. Available in index=cloud-azure sourcetype=azure:monitor:aad. |
| Azure Audit Logs | T1078, T1485 | Azure audit logs for MDM/Intune action detection. Available in index=cloud-azure sourcetype=mscs:azure:audit. |
| CrowdStrike EDR | T1486, T1219, T1003.001, T1036.005 | EDR telemetry for process, file, and network activity. Available in index=crowdstrike. |
| Palo Alto Firewall | T1190, T1567.002 | Firewall logs for blocking/alerting on C2 IP connections. Available in index=firewall-pan sourcetype=pan:traffic:aggregated and pan:threat. |
| DNS Server Logs | T1567.002, T1190 | DNS server query logs as supplementary to Zeek DNS. Available in index=dns. |
| Windows Security Event Logs | T1078 | Logon events (4624/4625) for valid account abuse detection. Available in index=winevent sourcetype=XmlWinEventLog:Security. |
| PowerShell Script Block Logging | T1566 | PowerShell execution logging for detecting post-exploitation activity. Available in index=powershell. |
Recommendations
- Deploy all Medusa ransomware IOCs (7 IPs, 4 domains, 12+ filenames from CISA AA25-071A) into SIEM watchlists, EDR blocklists, and firewall deny rules immediately. Priority indicators: 83.138.53.139, 94.156.67.145, 45.61.150.94, erp.ranasons.com, gaze.exe, nezha-agent.exe, mimilib.dll.
- Audit all Microsoft Intune/Endpoint Manager Global Administrator and Device Administrator accounts for MFA enforcement, conditional access policies, and sign-in anomalies from unfamiliar IPs or impossible travel patterns, based on the Handala/Stryker Intune admin compromise precedent.
- Block unauthorized remote management tools (SimpleHelp, MeshAgent) at the perimeter and on endpoints if they are not provisioned IT tools. Create application control policies to prevent execution.
- Deploy Suricata rules (SIDs 2026001-2026012) on all network sensors to detect connections to Medusa C2 infrastructure, exfiltration domains, and Interactsh exploitation verification callbacks.
- Implement file integrity monitoring for rclone.exe and alert on any instances where the OriginalFileName PE metadata does not match the executing filename, to detect the lsp.exe masquerading technique.
- Set alerts in Intune/MDM audit logs for bulk device wipe, retire, or reset commands affecting more than 10 devices in any 24-hour window. This detection maps directly to the Handala destructive attack pattern.
- Inventory all Boston Scientific device dependencies across enterprise facilities. Query ERP/procurement systems for open purchase orders and cross-reference with surgical scheduling systems for procedures requiring BSX devices in the next 30 days. Identify alternative suppliers where possible.
- Review and harden all public-facing web applications against exploitation, given Medusa's documented use of T1190 (Exploit Public-Facing Application) for initial access. Prioritize patching of internet-exposed services.
- Deploy the Sigma rules provided in this report (Medusa batch script execution via PsExec, Intune admin activity, bulk device wipe commands, Medusa encryptor execution, renamed rclone, mimilib.dll, SimpleHelp/MeshAgent) across all Splunk and Elastic instances.
- Coordinate with Health-ISAC for updated ShinyHunters and FulcrumSec indicators, as these groups have also been actively targeting the healthcare/medtech sector throughout 2026.
Sources
- Update on recent cybersecurity incident - Boston Scientific Newsroom
- Boston Scientific says cyberattack disrupted operations globally - BleepingComputer
- Cyberattack Causes Global Disruption at Boston Scientific - SecurityWeek
- Medical device maker Boston Scientific says a cyberattack is causing a 'global disruption' to its operations - TechCrunch
- Boston Scientific discloses 'global disruption' in ongoing cyberattack - The Register
- Medical device maker Boston Scientific is being hit by a cyberattack. The shares are falling - CNBC
- Boston Scientific Cyberattack Impacting Operations - HIPAA Journal
- Shifts cancelled at Boston Scientific in Cork after cyberattack - Irish Examiner
- Boston Scientific Confirms Cyberattack That Affected Network Communications, Disrupting Global Operations - TechNadu
- Boston Scientific Cyberattack Disrupts Global Operations - Secureblink
- Boston Scientific Cyberattack Halts Shipments: Weeks of Device Delays Threaten Hospital Supply - TechTimes
- Boston Scientific Cyberattack Stalls Cardiac Device Supply Chain for Hospitals - TechTimes
- Boston Scientific impacted by ongoing cyberattack - Medical Device Network / Yahoo Finance
- Stryker breach makes medical device cybersecurity a boardroom issue - Today's Medical Developments
- Medtronic Notifies 3.8M Individuals About April 2026 Cyberattack - HIPAA Journal
- AmGen Announces Cyberattack and Data Breach (ShinyHunters/Health-ISAC alert context) - HIPAA Journal
- Cyberattacks have plagued the medtech industry in 2026 - MedTech Dive
- Boston Scientific Cyberattack Halts Shipments (supply chain / survey data) - TechTimes
- Boston Scientific says cyberattack disrupted order processing, shipping - Cybersecurity Dive
- #StopRansomware: Medusa Ransomware (AA25-071A) - CISA/FBI/HHS Joint Advisory