Medusa ransomware operators have compromised over 500 organizations across critical infrastructure sectors, according to a joint advisory issued by the FBI, CISA, and the U.S. Department of Health and Human Services (HHS) as part of their #StopRansomware initiative.
An update released on August 18, 2026, provides expanded intelligence based on FBI investigations conducted as recently as April 2026.
This ransomware campaign has impacted a wide range of organizations, including those in the healthcare, education, legal, insurance, technology, and manufacturing sectors. Notably, the Healthcare and Public Health sector continues to be a frequent target.
Medusa Ransomware
Medusa was first identified in June 2021 and is classified as a ransomware-as-a-service (RaaS) operation, distinct from MedusaLocker and Medusa mobile malware.
By early 2023, the operation transitioned from a closed ransomware group to an affiliate-based model, allowing developers to recruit external operators with varying levels of access and operational autonomy.
Medusa combines data encryption with data-theft extortion. Affiliates steal victim data before encrypting systems, then threaten to publish it on a Tor-based leak site unless a ransom is paid.
Victims are typically instructed to contact the group through a Tor chat portal or Tox messaging platform within 48 hours.
Operators may escalate pressure by contacting victims directly through email or telephone, publishing ransom amounts, cryptocurrency wallet links, claimed page-view counts, and countdown timers on their leak site.
The group also offers victims the option to pay $10,000 in cryptocurrency to extend the public data release countdown by one day.
FBI investigations found at least one victim was approached after paying a ransom by another Medusa actor demanding an additional payment for the supposed “true decryptor,” suggesting either a possible triple-extortion tactic or poor coordination between affiliates and core operators.
Initial Access and Exploitation
Medusa actors recruit initial access brokers on cybercriminal forums, reportedly offering between $100 and $1 million for access to victim networks. They rely heavily on phishing and exploitation of unpatched internet-facing applications.
Observed exploited vulnerabilities include:
- CVE-2024-1709 in ConnectWise ScreenConnect.
- CVE-2023-48788, a Fortinet EMS SQL injection flaw.
- CVE-2025-10035 in Fortra GoAnywhere MFT.
- CVE-2026-1731, a remote code execution vulnerability affecting BeyondTrust Remote Support and Privileged Remote Access.
The advisory warns that Medusa operators may weaponize newly announced exploits within 24 hours and have, in some cases, used exploits up to a week before public disclosure.
They use Interactsh domains, including oast[.]site, oast[.]pro, and oast[.]fun, to confirm whether exploit attempts successfully reached vulnerable systems.
After gaining access, affiliates use legitimate tools and living-off-the-land techniques to reduce detection. Their discovery activity includes PowerShell, cmd.exe, WMI, Advanced IP Scanner, SoftPerfect Network Scanner, and CrackMapExec/NetExec.
The actors have used RMM platforms already present in victim environments, including AnyDesk, Atera, ConnectWise, BeyondTrust, N-able, SimpleHelp, Splashtop, and eHorus. They combine these tools with RDP and PsExec for lateral movement.
Credential theft techniques include LSASS dumping via Mimikatz, Task Manager, and comsvcs.dll; using mimilib.dll to log plaintext credentials; and abusing Volume Shadow Copy to steal ntds.dit and registry hives. This activity can enable a domain-wide compromise and the forging of Kerberos tickets.
For exfiltration, Medusa uses Bandizip to archive files and Rclone to transfer data. The ransomware payload, commonly named gaze.exe on Windows and gaze.py on Linux, encrypts files with AES-256 and appends the .medusa extension.
Key Indicators of Compromise
| IOC | Type | Associated Activity |
|---|---|---|
| 143.244.47[.]89 | IP address | PHP web shell access |
| 167.88.166[.]173 | IP address | Ligolo proxy infrastructure |
| 143.110.243[.]154 / erp.ranasons[.]com | IP/domain | Data exfiltration |
| 83.138.53[.]139 | IP address | Nezha backdoor server |
| 37.221.66[.]239 | IP address | Bash reverse-shell destination |
| 185.135.86[.]185 | IP address | SimpleHelp session |
| 85.155.186[.]121 | IP address | SimpleHelp session |
| 94.156.67[.]145 | IP address | Backdoor infrastructure |
!!!READ_ME_MEDUSA!!!.txt | File | Medusa ransom note |
nezha-agent.exe | File | Nezha monitoring/backdoor agent |
mimilib.dll | File | Mimikatz password logger |
openrdp.bat | File | Enables inbound RDP and remote WMI |
Ngconf.txt | File | Renamed Rclone configuration file |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC
Click Here For The Original Source.
