Bing and Cortana source code reportedly stolen by Medusa ransomware crew

Ransomware attack on a computer
(Image credit: Kaspersky)

Threat actors going by “Medusa” have posted a new database on their leak site, claiming it contains data from Microsoft including source code for Bing and Cortana. 

Found by Emsisoft researcher Brett Callow, the announcement says embedding the source code could trick antivirus products into confusing malware with Microsoft-made programs.

"This leak is of more interest to programmers, since it contains the source codes of the following Bing products, Bing Maps and Cortana," the announcement reads. "There are many digital signatures of Microsoft products in the leak. Many of them have not been recalled. Go ahead and your software will be the same level of trust as the original Microsoft product."

No confirmation

While the announcement did raise red flags all around, no threat analysts have yet confirmed the authenticity of Medusa’s claims, so the files might be bogus for all we know.

"At this point, it's unclear whether the data is what it's claimed to be," Emsisoft's Callow told The Register. "Also unclear is whether there's any connection between Medusa and Lapsus$ but, with hindsight, certain aspects of their modus operandi does have a somewhat Lapsus$ish feel."

A year ago, a threat actor called Lapsus$ announced breaking into Microsoft’s endpoints and stealing roughly 37GB of sensitive data, including the source code for Bing and Cortana. Soon afterward, Microsoft confirmed the breach but stated “no customer code or data” being taken. "Microsoft does not rely on the secrecy of code as a security measure and viewing source code does not lead to elevation of risk," the Redmond giant explained at the time. 

Thus, Callow could be suggesting that the attackers were just re-leaking what was already stolen a year ago.

Medusa is a ransomware operator that rose to infamy after breaching the Minneapolis Public Schools (MPS) district and demanding $1 million in exchange for the decryption key. Given that MPS’ data was leaked to the dark web soon after, it’s safe to assume that the negotiations fell through. 

Via: The Register

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Code Skull
US government warns Medusa ransomware has hit hundreds of critical infrastructure targets
hacker.jpeg
VSCode extensions pulled over security risks, but millions of users have already installed
hacker.jpeg
Thousands of GitHub repositories exposed via Microsoft Copilot
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
UK private health services firm told to pay up $2m for ransomware hit
Data leak
Details of over 15,000 FortiGate devices leaked online, so be on your guard
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
59 organizations reportedly victim to breaches caused by Cleo software bug
Latest in Security
Close up of a person touching an email icon.
Criminals are using CSS to get around filters and track email usage
DeepSeek on a mobile phone
More US government departments ban controversial AI model DeepSeek
Ransomware
Fortinet firewall bugs are being targeted by LockBit ransomware hackers
Trojan
Microsoft warns of a devious new RAT malware which can avoid detection with apparent ease
NordProtect logo
Standalone identity theft protection from Nord Security is now available
A man holds a smartphone iPhone screen showing various social media apps including YouTube, TikTok, Facebook, Threads, Instagram and X
Ofcom cracks down on UK tech firms, will issue sanctions for illegal content
Latest in News
Helly and Mark standing on an artificial hill surrounded by goats in Severance season 2 episode 3
New Apple teaser for Severance season 2 finale suggests we might finally find out what Lumon is doing with those goats, and I don't think it's anything good
Marvel Rivals
Marvel Rivals' next update will add two new hero skins for Iron Man and Spider-Man mains this week
Nvidia Isaac GROOT N1
“The age of generalist robotics is here" - Nvidia's latest GROOT AI model just took us another step closer to fully humanoid robots
Lego Pokemon
Pokemon and Lego announce the most electrifying collaboration of all time and I’m going to be first in line
Apple Watch app health
Apple Watch blood pressure monitoring tech revealed in patent
Using Zipped files and folders in Windows 11
Hidden clues suggest Microsoft is moving another part of Windows 11’s Control Panel to the Settings app – and this time it’s mouse options