US Agencies Update Medusa Ransomware Warning As Victim Count Surpasses 500 | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


U.S. Cybersecurity and Infrastructure Security Agency CISA and law-enforcement have issued an expanded warning about the Medusa ransomware operation after federal investigations identified more than 500 affected organisations across critical infrastructure and other industries.

The updated joint advisory, published on August 18 by the Cybersecurity and Infrastructure Security Agency, the FBI and the Department of Health and Human Services, incorporates tactics, techniques, procedures and indicators of compromise observed in FBI investigations as recently as April 2026.

The figure represents a substantial increase from the more than 300 victims documented when the original advisory was released in March 2025. In little more than a year, federal investigators identified at least 200 additional organisations affected by the operation, although the true number is likely to be higher because many ransomware incidents are never publicly disclosed or reported to law enforcement.

Healthcare and public health organisations feature prominently in the latest warning. Attacks against hospitals, medical providers and organisations holding health information can have consequences extending well beyond the theft of corporate data, including the interruption of clinical systems, delayed appointments, ambulance diversions and reduced access to patient records.

“Medusa is a ransomware-as-a-service variant that has impacted more than 500 victims across a range of critical infrastructure sectors and industries—including frequent attacks against the Healthcare and Public Health Sector,” CISA said when announcing the update.

The revised federal advisory indicates that Medusa’s operators and affiliates are not relying on one repeatable intrusion method. Instead, they combine purchased network access, phishing, stolen credentials, rapidly weaponised vulnerabilities and legitimate administrative software to enter and move through victim environments.

Medusa Exploiting Vulnerabilities Within 24 Hours

One of the most significant findings in the updated advisory is the speed with which Medusa actors respond to newly available vulnerability information.

CISA and the FBI said the attackers have exploited newly announced vulnerabilities within 24 hours of disclosure. In some investigations, the group was observed using exploits as much as a week before the relevant vulnerability was publicly disclosed.

That finding does not necessarily mean Medusa develops previously unknown vulnerabilities. The agencies said they had found no indication that the group independently creates its own zero-day or “N-day” exploits. Instead, the operation appears to obtain advanced access to exploit code from unknown sources or move exceptionally quickly once technical details become available.

The distinction matters for defenders. An organisation that treats vendor disclosure as the beginning of a conventional multi-week patch cycle may already be exposed by the time its vulnerability-management process begins. Internet-facing security appliances, remote-access products, management platforms and collaboration servers are especially attractive because a successful exploit can provide a direct route into a corporate network without requiring a malicious document to reach an employee.

The federal warning reinforces the need for organisations to monitor vulnerability disclosures continuously, identify exposed products in real time and have an emergency remediation process for flaws likely to be exploited. Prioritisation should consider active exploitation, internet exposure and the business importance of the affected system—not simply a vulnerability’s severity score.

CISA’s updated assessment says Medusa has previously targeted vulnerabilities affecting ConnectWise ScreenConnect and Fortinet FortiClient Enterprise Management Server, alongside weaknesses in Microsoft Exchange and other public-facing infrastructure. The operation also monitors vulnerability announcements to identify organisations that have not yet installed available security updates.


From Closed Operation to Ransomware-as-a-Service

Medusa was first identified in June 2021 and originally operated as a closed ransomware group in which the same core team controlled malware development and related criminal activity.

The operation subsequently adopted an affiliate model, allowing other cybercriminals to use Medusa ransomware in attacks. However, it differs from some decentralised ransomware programmes because the core developers appear to retain control over important parts of the business.

According to the federal advisory, less experienced affiliates may have ransom negotiations handled centrally by the developers. More established operators may receive greater autonomy based on their experience and previous earnings.

This hybrid structure gives Medusa access to a broader range of intrusion specialists without surrendering complete control of its brand, leak infrastructure and monetisation process. It also makes individual incidents less predictable because different affiliates may use different tools and entry techniques before deploying the same ransomware payload.

Medusa should not be confused with MedusaLocker, a separate ransomware family, or the Android banking malware also known as Medusa. The FBI considers the three threats unrelated.

Initial Access Brokers Expand the Attack Surface

The updated advisory places additional emphasis on Medusa’s recruitment of initial access brokers—criminal specialists who compromise corporate networks and then sell that access to ransomware operators.

Initial access brokers can obtain entry through phishing, credential theft, password spraying, compromised remote desktop services, vulnerable VPN devices or exploitation of internet-facing applications. By purchasing access, a ransomware operation can avoid conducting every stage of an intrusion itself and move more quickly to privilege escalation, data theft and encryption.

Medusa has reportedly recruited these brokers through cybercriminal forums and marketplaces, offering payments ranging from $100 to as much as $1 million. The largest offers are associated with high-value access or agreements to work exclusively with the operation.

The use of brokers also complicates attribution. The activity used to gain initial entry may differ considerably from the behaviour observed later in the intrusion because separate criminal teams can be responsible for each phase. The credentials or access sold to Medusa may also have been offered to other groups, creating the possibility that more than one threat actor is present in a network.

Security teams should consequently avoid assuming that removing an identified ransomware payload or remote-access tool has eliminated the original access path. Incident responders need to determine how the first compromise occurred, which accounts were exposed and whether additional persistence mechanisms or unauthorised users remain.

Trusted Tools Used to Conceal Malicious Activity

After gaining access, Medusa actors frequently employ living-off-the-land techniques and commercially available administration software instead of relying exclusively on custom malware.

Legitimate applications are useful to attackers because their presence may not immediately trigger a security alert. Remote monitoring and management products are routinely used by internal IT departments, contractors and managed service providers, making malicious activity harder to distinguish from authorised support work.

The FBI has observed Medusa actors using products including AnyDesk, Atera, ConnectWise, eHorus, N-able, BeyondTrust, SimpleHelp and Splashtop. The inclusion of these names does not indicate that the products themselves are malicious; rather, valid or attacker-created accounts can allow the software to be misused as a persistent remote-control channel.

Earlier Medusa investigations also documented the use of tools such as Advanced IP Scanner and SoftPerfect Network Scanner for internal discovery. Attackers can use such utilities to identify servers, endpoints, shared storage, administrative interfaces and systems reachable through remote services.

PowerShell, Windows command-line utilities, scheduled tasks and registry changes may be used to execute code, maintain access or alter security settings. Medusa activity has also included attempts to enable Remote Desktop, change firewall rules and create local accounts.

Credential theft is a critical part of the operation. Once attackers obtain administrative credentials, they can move laterally using legitimate authentication mechanisms, reach high-value servers and distribute ransomware through tools that administrators normally use to deploy software.

This is why identifying only the final encryption executable is insufficient. By the time mass encryption begins, attackers may have spent hours or days collecting credentials, mapping the network, disabling security controls and stealing data.

Double Extortion Creates Two Separate Crises

Medusa uses a double-extortion model. Before or alongside encrypting files, attackers steal information and threaten to publish it if the victim refuses to pay.

This creates two distinct incidents: an operational disruption caused by encrypted systems and a data breach involving potentially sensitive information. Restoring from backups may address the first problem, but it does not prevent attackers from releasing data they have already removed.

Medusa maintains a dark-web leak site where it identifies victims, publishes ransom demands and displays countdown timers indicating when stolen information may be released. The operation has also advertised stolen data to prospective buyers while negotiations are underway.

Victims have reportedly been offered the option of paying $10,000 in cryptocurrency to extend the countdown by a single day. This tactic turns time itself into an extortion mechanism, increasing pressure on executives as legal, regulatory and incident-response teams attempt to determine what information was taken.

The FBI has also documented behaviour that may represent triple extortion or internal dysfunction within the group. In one case, a separate Medusa actor approached a victim after a ransom had reportedly been paid, claimed that the original negotiator had stolen the money and demanded an additional payment for the “true” decryptor.

The incident highlights a fundamental problem with ransom payment: victims are dealing with a criminal ecosystem that offers no enforceable guarantees. Payment does not prove that stolen information has been destroyed, that a decryptor will work or that another affiliate will not make a second demand.

Federal agencies continue to discourage ransom payments because they fund criminal activity, encourage further attacks and provide no assurance of recovery. Organisations are urged to report incidents regardless of whether a payment has been made.

Healthcare Remains a High-Impact Target

The participation of HHS in the updated advisory reflects the continued danger to the healthcare and public health sector.

Healthcare organisations are attractive to ransomware operators because they possess sensitive personal and medical information while depending on continuous access to digital systems. Electronic health records, imaging platforms, pharmacy systems, laboratory services, scheduling, billing and communications may all be affected by a major network shutdown.

That operational pressure can make a hospital appear more likely to pay, particularly when prolonged disruption could affect patient care. At the same time, the theft of medical records creates considerable privacy, legal and regulatory consequences.

Medusa’s attack against the University of Mississippi Medical Center demonstrated the potential scale of this risk. The institution operates Mississippi’s only children’s hospital, its only Level I trauma centre, its only Level IV neonatal intensive care unit and the state’s only organ-transplant programme. The incident caused extensive disruption and heightened law-enforcement attention toward the ransomware operation, according to Recorded Future News’ coverage of the updated advisory.

The group has not added a publicly identified victim to its leak site since April 2026. That pause should not be interpreted as proof that Medusa has disappeared. Ransomware operations may temporarily reduce public activity, change infrastructure, reorganise their affiliate programmes or conduct negotiations without publishing a victim’s name.

Victim Count Rises From 300 to More Than 500

When CISA, the FBI and the Multi-State Information Sharing and Analysis Center released the original Medusa advisory in March 2025, investigators said the operation had affected more than 300 victims across sectors including healthcare, education, legal services, insurance, technology and manufacturing.

By April 2026, that figure had risen above 500.

The increase illustrates both the longevity of the operation and the resilience of the ransomware-as-a-service model. Disruptions targeting individual ransomware brands do not necessarily remove the brokers, credential thieves, malware developers, negotiators and money-laundering services supporting the wider ecosystem.

Medusa has also demonstrated unusually public extortion tactics. Unit 42 previously documented the operation’s use of its Medusa Blog leak site and a public Telegram channel to amplify stolen material and place additional pressure on victims. Researchers observed the group offering several paid options, including extending publication deadlines or allegedly deleting stolen information. Unit 42’s analysis described this as an escalation from conventional ransomware toward a broader multi-extortion strategy.

Public victim counts must nevertheless be interpreted cautiously. Leak-site entries show only organisations that attackers choose to name. They do not include every intrusion, unsuccessful attack, privately settled case or incident that was contained before encryption.

Three Immediate Priorities for Defenders

CISA has highlighted three actions organisations should take immediately: remediate known vulnerabilities within a risk-informed timeframe, segment networks to constrain lateral movement and filter traffic so that only legitimate sources can reach internal remote services.

Those priorities address multiple stages of the Medusa attack chain.

Rapid vulnerability remediation can block entry through public-facing systems. Where an update cannot be installed immediately, organisations should consider temporary isolation, disabling the affected service, limiting access through an allowlist or deploying vendor-provided mitigations.

Network segmentation can prevent a compromise of one user workstation, remote-access server or subsidiary environment from becoming an enterprise-wide ransomware incident. Critical servers, backup infrastructure, identity systems, healthcare equipment and operational technology should not be reachable through unrestricted flat networks.

Traffic filtering can reduce exposure to Remote Desktop Protocol, Server Message Block, Secure Shell and administrative interfaces. Remote services should not be accessible from arbitrary internet addresses, and internal management ports should be limited to authorised administrative systems.

The agencies also recommend multifactor authentication for webmail, VPNs and accounts that access critical systems. Where possible, organisations should use phishing-resistant methods rather than relying entirely on text messages or easily approved push notifications.

Administrators should maintain offline or otherwise isolated backups, regularly test restoration procedures and ensure attackers cannot use compromised domain credentials to delete or encrypt every recovery copy. Backups need to support recovery of identity services, configuration data and critical applications—not only user documents.

Security teams should also monitor for the unexpected installation or execution of remote-management tools. Organisations that legitimately use products such as AnyDesk, ConnectWise or Splashtop should establish an approved inventory and alert when an unapproved instance appears, when a new tenant is configured or when a tool connects to unfamiliar infrastructure.

Incident Response Must Begin Before Encryption

The updated warning demonstrates that the best opportunity to stop Medusa may come before ransomware is deployed.

Possible early indicators include exploitation attempts against public-facing products, suspicious PowerShell activity, unauthorised remote-management installations, creation of new administrative users, credential dumping, high-volume internal scanning and unusual transfers of data to external services.

An organisation that detects these behaviours should not wait for file encryption before declaring an incident. Administrators should isolate affected systems, preserve logs and volatile evidence, disable compromised accounts, examine identity infrastructure and determine whether data is being staged or exfiltrated.

Investigators should review authentication logs, endpoint telemetry, VPN activity, remote-access records, scheduled tasks, registry changes and outbound transfers. Because Medusa affiliates may use legitimate tools, responders must analyse the context in which a process ran rather than treating the presence of a signed application as evidence that activity was authorised.

The FBI and CISA request that ransomware incidents be reported through the FBI’s Internet Crime Complaint Center, a local FBI field office or CISA’s incident-reporting channels. Useful evidence can include ransom notes, malicious files, cryptocurrency wallet addresses, attacker email addresses, Tor links, logs and details of communications with the criminals.

A Shrinking Window for Patch Management

The most important strategic message in the updated advisory is that the time available to respond to newly disclosed vulnerabilities is continuing to shrink.

Medusa’s reported ability to exploit vulnerabilities within 24 hours—and in some cases before public disclosure—means organisations cannot rely solely on monthly patching cycles. Security teams need accurate asset inventories, visibility into internet-facing services and an emergency process that can operate outside normal maintenance windows.

The rise from 300 to more than 500 identified victims shows that Medusa remains a persistent threat even as the ransomware market fragments and individual groups change their branding or business structure.

For defenders, the operation is a reminder that ransomware prevention is not a single security product or patch. It is a combination of exposure management, identity protection, segmentation, controlled remote access, behavioural detection, resilient backups and a response plan capable of containing an intrusion before data theft and encryption turn it into a full-scale crisis.

Article content

Article content

——————————————————–


Click Here For The Original Source.

.........................