Security Affairs
Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback|Australian Police Charge Two Over TeamPCP Credential Theft|Meta to Pay Up to $18B Over Teen Social Media Use|CISA Warns Water Utilities: Find Your Exposed PLCs Before Attackers Do|OpenAI banned Russian ChatGPT accounts backing covert influence operation|CISA Red Team Fully Compromised Two Critical Infrastructure Orgs|FBI Seizes China-Linked Hacking Platforms QScan and QTRouter Used Against Critical Infrastructure|U.S. CISA adds Gitea flaw to its Known Exploited Vulnerabilities catalog|88 ID Verification Breaches Show the Cost of Collecting Identity Data|WhatsApp Adds Stronger Security as Passkeys Hit 1 Billion|Operation Jackal: 58 Arrests Expose the Money Laundering Machine Behind Global Scams|Norway ’s Digital Government Infrastructure Hit by a new DDoS Attack|Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback|Australian Police Charge Two Over TeamPCP Credential Theft|Meta to Pay Up to $18B Over Teen Social Media Use|CISA Warns Water Utilities: Find Your Exposed PLCs Before Attackers Do|OpenAI banned Russian ChatGPT accounts backing covert influence operation|CISA Red Team Fully Compromised Two Critical Infrastructure Orgs|FBI Seizes China-Linked Hacking Platforms QScan and QTRouter Used Against Critical Infrastructure|U.S. CISA adds Gitea flaw to its Known Exploited Vulnerabilities catalog|88 ID Verification Breaches Show the Cost of Collecting Identity Data|WhatsApp Adds Stronger Security as Passkeys Hit 1 Billion|Operation Jackal: 58 Arrests Expose the Money Laundering Machine Behind Global Scams|Norway ’s Digital Government Infrastructure Hit by a new DDoS Attack|
Advertisement

Ad Placeholder

Full Width × 90

Breaking News

MedusaLocker ransomware group is looking for pentesters

MedusaLocker ransomware gang announced on its Tor data leak site that it is looking for new pentesters. MedusaLocker is a ransomware strain that was first observed in late 2019, it encrypts files on infected systems and demands a ransom, usually in cryptocurrency, for their decryption. The group operates as Ransomware-as-a-Service (RaaS), meaning affiliates can rent […]

MedusaLocker

MedusaLocker ransomware gang announced on its Tor data leak site that it is looking for new pentesters.

MedusaLocker is a ransomware strain that was first observed in late 2019, it encrypts files on infected systems and demands a ransom, usually in cryptocurrency, for their decryption.

The group operates as Ransomware-as-a-Service (RaaS), meaning affiliates can rent the ransomware in exchange for a cut of the profits.

MedusaLocker ransomware gang announced on its Tor data leak site that it is looking for new pentesters.

MedusaLocker

Why Would a Ransomware Gang Hire a Pen Tester?

It may sound strange at first, the kind of job ad you’d expect to find on LinkedIn, not on a dark web forum, but in the cybercriminal underground, recruiting skilled penetration testers is not uncommon. In fact, it’s a natural evolution of the ransomware economy. Just as legitimate companies hire security professionals to test and strengthen their defenses, ransomware operators are hiring them to probe, map, and exploit weaknesses in target networks. The difference is in the intent: one aims to protect, the other to profit through extortion.

Modern ransomware operations function like structured businesses. They have management hierarchies, technical teams, customer support for victims, negotiators, and, increasingly, talent scouts. For affiliates to maximize profits, they need skilled people to identify valuable targets and ensure access is deep and persistent.

This is where pen testers come in. In the legitimate world, penetration testers simulate attacks to reveal vulnerabilities, often using the same tools and techniques as real hackers, vulnerability scanners, phishing campaigns, password-cracking tools, and lateral movement exploits. In the criminal world, these skills are repurposed to map high-value systems, disable backups, exfiltrate sensitive data, and prepare the ground for maximum-impact ransomware deployment.

Hiring a pen tester offers several advantages to threat actors:

  1. Efficiency – A skilled tester can quickly identify exploitable entry points, reducing the time between initial compromise and ransom deployment.
  2. Stealth – Experienced testers understand operational security (OpSec) and can evade detection while mapping the network.
  3. Profit Maximization – The deeper the access, the more leverage for ransom demands. Pen testers help locate sensitive data and critical systems to encrypt first.
  4. Outsourcing Risk – By contracting specialized talent, core members of the ransomware gang limit their own exposure.

On underground forums, ads for “red teamers” or “network penetration specialists” appear with surprising regularity. They often require proficiency in Active Directory exploitation, privilege escalation, and familiarity with enterprise tools like VMware or Citrix, all critical in corporate environments. Payment is typically commission-based, meaning pen testers earn a percentage of each successful ransom, sometimes reaching six-figure payouts for a single job.

When ransomware gangs look for pen testers, it’s not about breaking into a system for fun, it’s a calculated business decision. By recruiting skilled professionals, they can operate with the precision, efficiency, and profitability of a legitimate penetration testing firm… with the sole purpose of holding victims hostage for millions.

MedusaLocker group is looking for pen tester to target ESXi, Windows, and also ARM based systems. The announcement published by the group also require direct access to corporate networks to speed up attack’s execution.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, MedusaLocker)