Medusa Ransomware Hits 40+ Victims in 2025, Demands $100K
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-48788 | Unauthenticated SQL Injection in Fortinet FortiClient EMS Fortinet FortiClient EMS — the central management server for FortiClient endpoint deployments — contains a SQL injection flaw (CWE-89) in versions 7.0.1 through 7.0.10 and 7.2.0 through 7.2.2. The CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N) shows it can be triggered remotely with no credentials and no user interaction: an unauthenticated attacker sends specially crafted packets to the vulnerable management server and can execute unauthorized code or commands. Successful exploitation effectively yields remote code execution on the EMS server and access to its database, enabling follow-on actions such as credential theft, abuse of endpoint management functions, and ransomware deployment. Any organization running the affected EMS versions is exposed, especially where the management server is reachable from the internet. Exploitation is confirmed in the wild: CISA added the bug to the KEV catalog on 2024-03-25 with known ransomware use, and EPSS assigns a ~98.4% probability of exploitation within 30 days (100th percentile). Do: Upgrade FortiClient EMS to the fixed releases per Fortinet's advisory for this CVE (7.2.3 and 7.0.11 or later, i.e., beyond the 7.2.2 and 7.0.10 affected ranges); the CISA KEV required action is to apply vendor mitigations or discontinue use if mitigations are unavailable. Until patched, limit exposure of the EMS web interface to untrusted networks and hunt for signs of compromise — anomalous requests to the management console, unexpected database or admin activity, and follow-on ransomware behavior — since exploitation with known ransomware use is confirmed. | 9.8 | 98% | KEV ransomware |
| largetens of thousands of EMS deployments worldwide, with a smaller subset (likely thousands) internet-exposed | |
| CVE-2024-1709 | Authentication Bypass in ConnectWise ScreenConnect Creates Rogue Admin Accounts ConnectWise ScreenConnect (ConnectWise Control), a widely used remote-access and remote-monitoring tool, contains an authentication bypass (CWE-288) in its management interface. An attacker needs only network access to the management interface to trigger the flaw, with no valid credentials or user interaction required. A successful attacker gains administrative control of the ScreenConnect server by creating a new administrator-level account, providing a foothold that has already been used in ransomware campaigns against downstream managed environments. Any organization running ConnectWise ScreenConnect is affected, especially managed service providers and IT teams whose management interface is reachable from the internet; the source data specifies affected products but no version ranges. Exploitation is confirmed and urgent: CISA added the flaw to the KEV on 2024-02-22 with known ransomware use, EPSS assigns a 100% probability of exploitation within 30 days, and ConnectWise warned that no patch was available at the time of disclosure. Do: Follow ConnectWise's instructions immediately: no patch existed at disclosure, so apply the vendor's mitigations or, per the CISA KEV required action, restrict internet exposure of the management interface or discontinue use until mitigations are available, then upgrade to the vendor's patched release as soon as it ships. Audit ScreenConnect servers for unexpectedly created administrator-level accounts and unusual remote sessions, which are the attack's artifacts. Prioritize any instance whose management interface is reachable from the internet, given confirmed in-the-wild exploitation and known ransomware use. | 10.0 | 100% | KEV ransomware PoC ×3 |
| masstens of thousands of internet-exposed ScreenConnect servers (on the order of 10,000-30,000 instances in public internet scans at disclosure), managing millions… |
Full article962 words · extracted from thehackernews.com · click to collapse
The threat actors behind the Medusa ransomware have claimed nearly 400 victims since it first emerged in January 2023, with the financially motivated attacks witnessing a 42% increase between 2023 and 2024.
In the first two months of 2025 alone, the group has claimed over 40 attacks, according to data from the Symantec Threat Hunter Team shared with The Hacker News. The cybersecurity company is tracking the cluster under the name Spearwing.
"Like the majority of ransomware operators, Spearwing and its affiliates carry out double extortion attacks, stealing victims' data before encrypting networks in order to increase the pressure on victims to pay a ransom," Symantec noted.
"If victims refuse to pay, the group threatens to publish the stolen data on their data leaks site."
While other ransomware-as-a-service (RaaS) players like RansomHub (aka Greenbottle and Cyclops), Play (aka Balloonfly), and Qilin (aka Agenda, Stinkbug, and Water Galura) have benefited from the disruptions of LockBit and BlackCat, the spike in Medusa infections raises the possibility that the threat actor could also be rushing in to fill the gap left by the two prolific extortionists.
The development comes as the ransomware landscape continues to be in a state of flux, with a steady stream of new RaaS operations, such as Anubis, CipherLocker, Core, Dange, LCRYX, Loches, Vgod, and Xelera, emerging in the wild in recent months.
Medusa has a track record of demanding ransoms anywhere between $100,000 up to $15 million from targeting healthcare providers and non-profits, as well as financial and government organizations.
Attack chains mounted by the ransomware syndicate involve the exploitation of known security flaws in public-facing applications, mainly Microsoft Exchange Server, to obtain initial access. It's also suspected that the threat actors are likely using initial access brokers for breaching networks of interest.
Once gaining a successful foothold, the hackers drop use remote management and monitoring (RMM) software such as SimpleHelp, AnyDesk, or MeshAgent for persistent access, and employ the tried-and-tested Bring Your Own Vulnerable Driver (BYOVD) technique to terminate antivirus processes using KillAV. It's worth pointing out that KillAV has been previously put to use in BlackCat ransomware attacks.
"The use of the legitimate RMM software PDQ Deploy is another hallmark of Medusa ransomware attacks," Symantec said. "It is typically used by the attackers to drop other tools and files and to move laterally across the victim network."
Some of the other tools deployed over the course of a Medusa ransomware attack include Navicat to access and run database queries, RoboCopy, and Rclone for data exfiltration.
"Like most targeted ransomware groups, Spearwing tends to attack large organizations across a range of sectors," Symantec said. "Ransomware groups tend to be driven purely by profit, and not by any ideological or moral considerations."
CISA Releases Medusa Advisory
In a joint cybersecurity bulletin released on March 12, 2025, the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the Multi-State Information Sharing and Analysis Center (MS-ISAC) noted that Medusa actors have claimed over 300 victims from critical infrastructure sectors as of December 2024.
Impacted industries include medical, education, legal, insurance, technology, and manufacturing. Medusa, the FBI added, is unrelated to the MedusaLocker variant and the Medusa mobile malware variant.
According to the agencies, the RaaS operation was first identified in June 2021, initially as a closed ransomware variant before switching to an affiliate-based model by recruiting outside members to conduct the double extortion attacks. However, crucial aspects such as ransom negotiation are said to be still overseen by the developers.
"Medusa actors use common techniques like phishing campaigns and exploiting unpatched software vulnerabilities," the alert said. The exploited flaws relate to ConnectWise ScreenConnect (CVE-2024-1709) and Fortinet EMS (CVE-2023-48788).
The threat actors have been observed using legitimate tools like Advanced IP Scanner, SoftPerfect Network Scanner, and remote access software, as well as other living-off-the-land (LotL) techniques, to perform reconnaissance, discovery, and lateral movement activities. The attacks are also characterized by various steps to evade detection -
- Deleting PowerShell command line history
- Using tunneling tools to kill or delete endpoint detection and response (EDR) tools
- Using tunneling tools like Ligolo and Cloudflared to support command-and-control (C2)
"After paying the ransom, one victim was contacted by a separate Medusa actor who claimed the negotiator had stolen the ransom amount already paid and requested half of the payment be made again to provide the 'true decryptor' – potentially indicating a triple extortion scheme," per the bulletin.
According to anti-ransomware and cyber resilience platform Halcyon, Medusa has emerged as one of the key frontrunners during the fourth quarter of 2024. The company also described it as a consistent threat group that has intensified its ransomware campaigns late in the year.
"Once inside a network, Medusa employs sophisticated strategies to maximize impact," Jon Miller, CEO and co-founder of Halcyon, said in a statement shared with The Hacker News. "The group executes Base64-encrypted commands via PowerShell to avoid detection and utilizes tools like Mimikatz to extract credentials from memory, facilitating further network compromise."
"They also leverage legitimate remote access software, including AnyDesk and ConnectWise, as well as tools like PsExec and RDP, to propagate across the network. The ransomware can terminate over 200 Windows services and processes, including those related to security software, to facilitate encryption."
To avoid falling victim to Medusa, organizations are recommended to store multiple copies of sensitive and/or proprietary data in an air-gapped location, enforce network segmentation to prevent lateral movement, implement multi-factor authentication, and keep software and systems up-to-date.
(The story was updated after publication to include details of a CISA advisory about Medusa ransomware.)
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/03/medusa-ransomware-hits-40-victims-in.html