Medusa Ransomware Tied to More Than 500 Critical Infrastructure Victims

U.S. agencies say Medusa ransomware has impacted more than 500 critical infrastructure victims while rapidly exploiting vulnerabilities and expanding its attack techniques.
Cybersecurity illustration of Medusa with glowing red eyes and black snakes, surrounded by red and white digital circuitry representing the Medusa ransomware threat.

Medusa ransomware has now impacted more than 500 victims across critical infrastructure sectors, according to a major update to a joint U.S. government advisory that provides new details on how the operation gains access, evades defenses, steals credentials, exfiltrates data, and deploys ransomware across compromised networks.

The Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), and Department of Health and Human Services (HHS) updated the advisory on August 18 with findings from FBI investigations conducted as recently as April 2026.

The new figure marks a significant increase from the more than 300 victims cited when the advisory was originally published in March 2025. The agencies said affected organizations span Healthcare and Public Health, the Defense Industrial Base, Critical Manufacturing, Government Services and Facilities, Information Technology, and Financial Services. Victims have also been identified in the medical, education, legal, insurance, technology, and manufacturing industries.

The complete 29-page updated Medusa ransomware advisory is available from the FBI’s Internet Crime Complaint Center.

Medusa races to exploit newly disclosed vulnerabilities

One of the most significant additions to the advisory concerns the speed at which Medusa affiliates capitalize on vulnerabilities.

The agencies describe Medusa as an opportunistic operation that searches for organizations running vulnerable software rather than restricting attacks to a narrow set of targets. Healthcare organizations have nevertheless been frequent victims.

According to the advisory, Medusa has exploited newly announced vulnerabilities within 24 hours and, in some cases, used exploits up to a week before public disclosure. The agencies said there is no indication that Medusa develops its own zero-day or N-day vulnerabilities. Instead, the operation appears to obtain early access to exploits from unknown sources or rapidly weaponize newly announced flaws before organizations can patch them.

Vulnerabilities associated with Medusa intrusions include ScreenConnect authentication bypass CVE-2024-1709, Fortinet EMS SQL injection vulnerability CVE-2023-48788, Fortra GoAnywhere vulnerability CVE-2025-10035, and BeyondTrust OS command injection vulnerability CVE-2026-1731.

The findings reinforce earlier research into Medusa’s aggressive exploitation strategy. BreachNews previously reported on Storm-1175 attacks using newly disclosed vulnerabilities to rapidly deploy Medusa ransomware.

The government advisory also documents Medusa using Interactsh dynamic URLs to determine whether exploitation attempts succeeded, allowing operators to identify vulnerable hosts before moving deeper into targeted networks.

Access brokers feed the ransomware operation

Medusa was first identified in June 2021 and initially operated as a closed ransomware operation. Since at least early 2023, it has evolved into a ransomware-as-a-service model in which affiliates receive varying levels of access based on their experience and profitability.

The updated advisory provides additional insight into the operation’s reliance on initial access brokers. Medusa reportedly recruits brokers through cybercriminal marketplaces and offers payments ranging from $100 to as much as $1 million for access to potential victims, along with opportunities to work exclusively for the ransomware operation.

Initial compromise commonly involves phishing to steal credentials or exploitation of vulnerable internet-facing software.

Once inside a network, Medusa operators rely heavily on legitimate administrative utilities and living-off-the-land techniques. FBI investigations observed the use of PowerShell, Windows Command Prompt, Windows Management Instrumentation, Advanced IP Scanner, and SoftPerfect Network Scanner for discovery and enumeration.

Legitimate remote tools help Medusa blend in

The updated findings show an operation willing to adapt its tooling to the victim environment rather than relying on a single recognizable attack chain.

Medusa affiliates have used legitimate remote monitoring and management software including AnyDesk, Atera, ConnectWise, eHorus, N-able, BeyondTrust, SimpleHelp, and Splashtop. The advisory says attackers may select remote access software based on tools already present in the compromised environment, potentially making malicious activity harder to distinguish from legitimate administration.

Operators combine these tools with Remote Desktop Protocol and PsExec for lateral movement, while credential theft can involve Mimikatz, Windows Task Manager, and comsvcs.dll to dump LSASS memory.

The FBI has also observed Medusa using Volume Shadow Copy to obtain Windows database and registry files that can be used to forge Kerberos tickets, potentially giving attackers control across an Active Directory domain.

Another newly documented technique involves modifying Active Directory Default Domain Policy settings. According to the advisory, Medusa operators have configured their malicious policy as “Enabled, Enforced,” allowing it to override more restrictive Group Policy settings that could otherwise interfere with the attack.

Data theft comes before encryption

Medusa follows a double-extortion model, stealing information before encrypting systems and threatening to publish the stolen data if victims refuse to pay.

FBI investigations found operators using Bandizip to package files and Rclone to transfer stolen information to Medusa-controlled infrastructure. Smaller collections, including credential files and registry hives, have also been transferred using RDP’s built-in file transfer capabilities.

For ransomware deployment, Medusa has used PsExec, PDQ Inventory and Deploy, and BigFix to distribute its Windows encryptor, gaze.exe, across victim environments. On Linux systems, operators have transferred the gaze.py encryptor using SFTP.

The Windows encryptor terminates services associated with backups, security software, databases, communications, file sharing, and websites before deleting shadow copies and encrypting files with AES-256. Encrypted files receive the .medusa extension.

The advisory also says Medusa operators have remotely shut down virtual machines before encrypting them and have abused ESXi administration services to change root passwords on Linux systems.

FBI investigation exposes problems inside the extortion model

The government’s update provides an unusual glimpse into Medusa’s ransom negotiations and apparent internal dysfunction.

Medusa typically demands that victims establish contact within 48 hours and uses its data leak operation to pressure organizations into paying. Attackers research victims’ financial information and reportedly use publicly available revenue figures when setting ransom demands. They may also offer temporary discounts intended to accelerate negotiations.

In one case investigated by the FBI, however, a victim that had already paid was contacted by a separate Medusa operator who claimed the original negotiator had stolen the payment. The second operator demanded another payment equal to half of the original ransom in exchange for what was described as the real decryptor.

The agencies said the incident could indicate a form of triple extortion, or alternatively operational dysfunction and a lack of cohesion inside the ransomware organization.

The FBI also cautioned that there is no way to verify Medusa’s claims that stolen victim information is actually deleted after payment.

Defenders urged to close the exploitation window

The updated advisory emphasizes patching as one of the most important defenses against Medusa, particularly given evidence that affiliates move quickly after vulnerabilities become exploitable.

CISA, the FBI, and HHS recommend prioritizing patches for known exploited vulnerabilities on internet-facing systems, implementing phishing-resistant multifactor authentication, segmenting networks to restrict lateral movement, limiting remote services to trusted origins, auditing privileged accounts, and maintaining encrypted and immutable offline backups.

Organizations should also monitor for unauthorized scanning, unexpected remote access software, newly created accounts, abnormal network traffic, and activity associated with legitimate tools that Medusa has been observed abusing.

If attackers are discovered before encryption begins, the agencies recommend isolating compromised systems, collecting evidence and logs to determine the scope of the intrusion, rotating privileged credentials, removing unauthorized command-and-control or remote access tooling, and patching the vulnerability used for initial entry.

The updated advisory also contains new indicators of compromise, malicious file hashes, MITRE ATT&CK mappings, incident response guidance, and commands observed during FBI investigations of Medusa intrusions.

The FBI, CISA, and HHS advise organizations against paying ransoms because payment does not guarantee recovery of encrypted files or deletion of stolen information.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site