The Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), and Multi-State Information Sharing and Analysis Center (MS-ISAC) have issued a joint advisory warning that Medusa ransomware operators continue to target critical infrastructure organizations through data theft, endpoint security evasion, and network-wide encryption operations.
Tracked as AA25-071A, the #StopRansomware advisory says Medusa developers and affiliates had impacted more than 300 organizations as of February 2025.
Confirmed victim sectors include healthcare, education, legal services, insurance, technology, and manufacturing. Federal investigators stressed that Medusa is unrelated to the MedusaLocker ransomware family or Medusa mobile malware.
CISA Warns Medusa Ransomware-as-a-Service Attacks
First identified in June 2021, Medusa began as a closed ransomware operation in which a single group controlled development and intrusions.
It has since evolved into a Ransomware-as-a-Service (RaaS) operation that recruits affiliates, while core developers retain control over important functions such as ransom negotiations.
The group uses a double-extortion model: affiliates steal data before applying encryption, then threaten to publish or sell it via a Tor-based leak site if the victim does not pay.
Victims are instructed to contact the operators within 48 hours via a Tor live chat portal or the encrypted Tox messaging platform.
Medusa also advertises stolen datasets to prospective buyers and allows victims to pay $10,000 in cryptocurrency to delay a leak countdown by one day.
Initial access brokers are central to the operation. The advisory says Medusa actors recruit brokers on criminal forums and marketplaces, offering between $100 and $1 million for access to corporate networks.
Phishing remains a major credential-theft method, while affiliates also exploit internet-facing vulnerabilities, including ConnectWise ScreenConnect (CVE-2024-1709) and Fortinet FortiClient EMS (CVE-2023-48788).
After gaining access, Medusa actors use living-off-the-land techniques to reduce detection. Investigators observed extensive use of PowerShell, cmd.exe, Windows Management Instrumentation, Certutil, and legitimate network-scanning utilities for discovery and payload delivery.
CISA stated that attackers also use legitimate remote management tools, including AnyDesk, Atera, ConnectWise, SimpleHelp, Splashtop, PDQ Deploy, and N-able, to move laterally within compromised networks.
Mimikatz has been used to dump LSASS credentials, while Rclone supports data exfiltration to attacker-controlled infrastructure. In some intrusions, actors deployed vulnerable or signed drivers to disable or remove endpoint detection and response tools.
The ransomware encryptor, commonly named gaze.exe, is distributed using PsExec, PDQ Deploy, or BigFix. Before encryption, it terminates backup, security, database, communication, file-sharing, and web-related services.
It deletes volume shadow copies, encrypts files with AES-256, and appends the .medusa extension. Operators may also shut down and encrypt virtual machines, maximizing operational disruption.
Federal agencies recommend immediate patching of internet-facing systems, especially known exploited vulnerabilities, alongside network segmentation to contain lateral movement.
Organizations should restrict and monitor remote access tools, require MFA for externally accessible services, audit privileged accounts, and investigate unrecognized domain accounts or RMM deployments.
Defenders should maintain multiple encrypted, immutable, offline backups and routinely test restoration procedures.
Security teams should also monitor for abnormal PowerShell activity, suspicious use of PsExec and Rclone, unauthorized RDP enablement, deleted command histories, and attempts to disable EDR or antivirus services.
| IOC | Type | Description |
|---|---|---|
| 143.244.47[.]89 | IP Address | IP used to access PHP Web Shell (Mullvad VPN) |
| 167.88.166[.]173 | IP Address | Ligolo proxy IP |
| https://3324.requestcatcher[.]com/hihi | URL | Additional URL associated with Ligolo commands |
| 143.110.243[.]154 aka erp.ranasons[.]com | IP Address & URL | Exfiltration IP/domain |
| 185.238.231[.]16 | IP Address | IP used to access BeyondTrust session (ExpressVPN) |
| 23.234.89[.]195 | IP Address | IP used to access BeyondTrust session (Mullvad VPN) |
| 146.70.172[.]247 | IP Address | IP used to access BeyondTrust session (Mullvad VPN) |
| 155.2.215[.]71 | IP Address | IP used to access BeyondTrust session |
| 23.234.106[.]242 | IP Address | IP used to access BeyondTrust session (Mullvad VPN) |
| 23.234.93[.]112 | IP Address | IP used to access BeyondTrust session (Mullvad VPN) |
| 37.19.21[.]180 | IP Address | IP used to access BeyondTrust session (Mullvad VPN) |
| 155.2.215[.]69 | IP Address | IP used to access BeyondTrust session |
| 185.238.231[.]98 | IP Address | IP used to access BeyondTrust session (ExpressVPN) |
| 37.221.66[.]239 | IP Address | Bash TCP reverse shell destination |
| 185.135.86[.]185 | IP Address | IP associated with SimpleHelp session |
| 83.138.53[.]139 | IP Address | IP associated with Nezha backdoor |
| 185.238.231[.]4 | IP Address | IP used to access BeyondTrust session (ExpressVPN) |
| 185.238.231[.]77 | IP Address | IP used to access BeyondTrust session (ExpressVPN) |
| 185.238.231[.]85 | IP Address | IP used to access BeyondTrust session (ExpressVPN) |
| 85.155.186[.]121 | IP Address | IP associated with SimpleHelp session |
| http//45.61.150[.]94:8000/storm[.]exe | URL | SimpleHelp agent was downloaded to victim using this IP |
| 94.156.67[.]145 | IP Address | IP associated with backdoor |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Give your security team the visibility and context to investigate suspicious activity faster and contain threats before business impact grows. Strengthen Your Investigations with ANY.RUN
Click Here For The Original Source.
