VORANT. Threat Intelligence Sign in Get the full feed

MedusaLocker claims Seznam via FortiOS flaw

high threat technology

Ransomware group MedusaLocker listed Czech firm Seznam as a victim, reportedly after SSL-VPN credentials were exposed via the FortiBleed (CVE-2022-40684) FortiOS vulnerability.

Ransomware.live's tracking of MedusaLocker's leak site lists Seznam as a new victim. The listing notes that the victim's FortiOS SSL-VPN credentials had previously been exposed through the FortiBleed leak (CVE-2022-40684), an authentication bypass in Fortinet's FortiOS/FortiProxy that allows unauthenticated attackers to read arbitrary files, including credentials, via crafted HTTP/HTTPS requests to the administrative interface. This suggests exposed or leaked Fortinet SSL-VPN credentials may have provided initial access for the intrusion, though the source article provides no further technical detail, IOCs, or confirmation of the intrusion chain.

MedusaLocker is an established ransomware-as-a-service operation known for opportunistic targeting across sectors, typically gaining initial access via exposed remote access services, RDP, or VPN vulnerabilities and phishing. Defenders using Fortinet SSL-VPN products should verify patch status against CVE-2022-40684, rotate any credentials that may have been exposed historically via this flaw, and audit VPN/remote-access logs for anomalous authentication from unrecognized sources. No further technical indicators, ransom note details, or confirmation of data exfiltration were provided in this listing.

Mentioned in this report

Vulnerabilities CVE-2022-40684KEV
Threat actors medusalocker
Malware MedusaLocker

Source reporting: https://www.ransomware.live/id/U2V6bmFtQG1lZHVzYWxvY2tlcg==

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free