Medusa Ransomware Attack on Gulf American Lines

Year

2023

Month

September

Reference number

20230902

Impact area

Shore

Incident location

USA

Incident country

USA

Victim country

USA

Victim identity

Gulf American Line

Victim Type

Freight forwarding, warehousing, and logistics provider

Method

Ransomware

Summary:

In September 2023, Gulf American Lines, a leading freight forwarding, warehousing, and logistics provider headquartered in Berkeley Heights, New Jersey, fell victim to a Medusa Locker ransomware attack. The attackers exploited an external web server, used web shells for access, and employed PowerShell for malicious activities, including disabling antivirus services. They utilized discovery and credential dumping techniques such as Mimikatz and Nishang, and established a reverse tunnel for command and control. Data was exfiltrated and later published on the Medusa leak site, with files encrypted and appended with .MEDUSA. The ransom demand was $100,000. The incident was reported by RedPacket Security, which emphasized its non-affiliation with any ransomware threat actors.

Reference URL

https://research.nccgroup.com/2023/11/13/dont-throw-a-hissy-fit-defend-against-medusa/
https://www.redpacketsecurity.com/medusalocker-ransomware-victim-gulf-american-lines/