CISA Warns of Medusa Ransomware-as-a-Service Attacks Over 300 Organizations | #ransomware | #cybercrime


The Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), and Multi-State Information Sharing and Analysis Center (MS-ISAC) have issued a joint advisory warning that Medusa ransomware operators continue to target critical infrastructure organizations through data theft, endpoint security evasion, and network-wide encryption operations.

Tracked as AA25-071A, the #StopRansomware advisory says Medusa developers and affiliates had impacted more than 300 organizations as of February 2025.

Confirmed victim sectors include healthcare, education, legal services, insurance, technology, and manufacturing. Federal investigators stressed that Medusa is unrelated to the MedusaLocker ransomware family or Medusa mobile malware.

CISA Warns Medusa Ransomware-as-a-Service Attacks

First identified in June 2021, Medusa began as a closed ransomware operation in which a single group controlled development and intrusions.

It has since evolved into a Ransomware-as-a-Service (RaaS) operation that recruits affiliates, while core developers retain control over important functions such as ransom negotiations.

The group uses a double-extortion model: affiliates steal data before applying encryption, then threaten to publish or sell it via a Tor-based leak site if the victim does not pay.

Victims are instructed to contact the operators within 48 hours via a Tor live chat portal or the encrypted Tox messaging platform.

Medusa also advertises stolen datasets to prospective buyers and allows victims to pay $10,000 in cryptocurrency to delay a leak countdown by one day.

Initial access brokers are central to the operation. The advisory says Medusa actors recruit brokers on criminal forums and marketplaces, offering between $100 and $1 million for access to corporate networks.

Phishing remains a major credential-theft method, while affiliates also exploit internet-facing vulnerabilities, including ConnectWise ScreenConnect (CVE-2024-1709) and Fortinet FortiClient EMS (CVE-2023-48788).

After gaining access, Medusa actors use living-off-the-land techniques to reduce detection. Investigators observed extensive use of PowerShell, cmd.exe, Windows Management Instrumentation, Certutil, and legitimate network-scanning utilities for discovery and payload delivery.

CISA stated that attackers also use legitimate remote management tools, including AnyDesk, Atera, ConnectWise, SimpleHelp, Splashtop, PDQ Deploy, and N-able, to move laterally within compromised networks.

Mimikatz has been used to dump LSASS credentials, while Rclone supports data exfiltration to attacker-controlled infrastructure. In some intrusions, actors deployed vulnerable or signed drivers to disable or remove endpoint detection and response tools.

The ransomware encryptor, commonly named gaze.exe, is distributed using PsExec, PDQ Deploy, or BigFix. Before encryption, it terminates backup, security, database, communication, file-sharing, and web-related services.

It deletes volume shadow copies, encrypts files with AES-256, and appends the .medusa extension. Operators may also shut down and encrypt virtual machines, maximizing operational disruption.

Federal agencies recommend immediate patching of internet-facing systems, especially known exploited vulnerabilities, alongside network segmentation to contain lateral movement.

Organizations should restrict and monitor remote access tools, require MFA for externally accessible services, audit privileged accounts, and investigate unrecognized domain accounts or RMM deployments.

Defenders should maintain multiple encrypted, immutable, offline backups and routinely test restoration procedures.

Security teams should also monitor for abnormal PowerShell activity, suspicious use of PsExec and Rclone, unauthorized RDP enablement, deleted command histories, and attempts to disable EDR or antivirus services.

IOCTypeDescription
143.244.47[.]89IP AddressIP used to access PHP Web Shell (Mullvad VPN)
167.88.166[.]173IP AddressLigolo proxy IP
https://3324.requestcatcher[.]com/hihiURLAdditional URL associated with Ligolo commands
143.110.243[.]154 aka erp.ranasons[.]comIP Address & URLExfiltration IP/domain
185.238.231[.]16IP AddressIP used to access BeyondTrust session (ExpressVPN)
23.234.89[.]195IP AddressIP used to access BeyondTrust session (Mullvad VPN)
146.70.172[.]247IP AddressIP used to access BeyondTrust session (Mullvad VPN)
155.2.215[.]71IP AddressIP used to access BeyondTrust session
23.234.106[.]242IP AddressIP used to access BeyondTrust session (Mullvad VPN)
23.234.93[.]112IP AddressIP used to access BeyondTrust session (Mullvad VPN)
37.19.21[.]180IP AddressIP used to access BeyondTrust session (Mullvad VPN)
155.2.215[.]69IP AddressIP used to access BeyondTrust session
185.238.231[.]98IP AddressIP used to access BeyondTrust session (ExpressVPN)
37.221.66[.]239IP AddressBash TCP reverse shell destination
185.135.86[.]185IP AddressIP associated with SimpleHelp session
83.138.53[.]139IP AddressIP associated with Nezha backdoor
185.238.231[.]4IP AddressIP used to access BeyondTrust session (ExpressVPN)
185.238.231[.]77IP AddressIP used to access BeyondTrust session (ExpressVPN)
185.238.231[.]85IP AddressIP used to access BeyondTrust session (ExpressVPN)
85.155.186[.]121IP AddressIP associated with SimpleHelp session
http//45.61.150[.]94:8000/storm[.]exeURLSimpleHelp agent was downloaded to victim using this IP
94.156.67[.]145IP AddressIP associated with backdoor

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Give your security team the visibility and context to investigate suspicious activity faster and contain threats before business impact grows. Strengthen Your Investigations with ANY.RUN



Click Here For The Original Source.

——————————————————–

..........

.

.