Medusa Ransomware Gang Attacks Over 500 Organizations, CISA Issues Warning
Medusa ransomware has compromised over 500 entities since its emergence in June 2021, according to a joint alert from the FBI, CISA, and the Department of Health and Human Services.
Medusa ransomware has compromised over 500 entities since its emergence in June 2021, according to a joint alert from the FBI, CISA, and the Department of Health and Human Services.
Key Details from the Advisory
The updated advisory expands on a previous statement issued in March 2025 and incorporates findings from FBI investigations conducted through April 2026. The report indicates that the Medusa group has targeted organizations across multiple critical infrastructure sectors, including healthcare, defense, manufacturing, government services, IT, and financial institutions. Additional affected sectors include education, insurance, and legal firms.
Evolution of the Medusa Group
The advisory details that Medusa initially functioned as a closed operation, with a single group managing all development and campaign activities. However, the threat actor transitioned to an affiliate model by early 2023, offering RaaS (Ransomware-as-a-Service) to third parties. Affiliates receive varying degrees of trust based on their track record and financial performance.
Access Acquisition and Attack Methods
The group acquires initial access through cybercriminal forums, paying between $100 and $1 million for entry points. Most access brokers are not exclusive to Medusa and often collaborate with multiple ransomware variants simultaneously. Medusa employs standard attack techniques, such as phishing to harvest credentials and exploiting unpatched software vulnerabilities.
Targeted Vulnerabilities
The advisory highlights specific weaknesses in ScreenConnect, Fortinet EMS, Fortra GoAnywhere, and BeyondTrust as recent targets. Affiliates act swiftly once vulnerabilities are disclosed, deploying exploits within 24 hours. The group does not develop its own zero-day exploits, relying instead on publicly available tools.
Encryption and Double-Extortion Strategy
Once inside a network, Medusa utilizes existing software rather than custom malware. Tools like PowerShell, Mimikatz for credential theft, and remote access platforms such as AnyDesk and SimpleHelp are commonly used. The encryption process is managed by a component called gaze.exe, which terminates backup and security services before locking files with the .medusa extension. The ransomware follows a double-extortion strategy.
Victim Demands and Timelines
Victims are given 48 hours to respond to a ransom demand before direct communication begins, with stolen data published on a leak site featuring a countdown timer. A $10,000 cryptocurrency payment grants an additional day.
Recommendations for Organizations
Agencies advise organizations to patch exposed systems, implement network segmentation to restrict movement, and block unauthorized traffic to remote access services. They also emphasize that paying ransoms is discouraged and urge victims to report incidents to the FBI’s Internet Crime Complaint Center or CISA.
