Medusa ransomware tallies hundreds of new victims, says updated advisory on group’s tactics
CISA, FBI, and HHS updated their Medusa ransomware advisory, reporting over 500 victims and detailing the gang's access-broker and exploit tactics.
A joint advisory update from CISA, the FBI, and HHS expands the March 2025 Medusa guidance, drawing on a year of FBI investigations. The ransomware-as-a-service group's known victim tally grew from more than 300 to more than 500 between March 2025 and April 2026, with the Healthcare and Public Health sector frequently hit. Medusa pays access brokers $100 to $1 million, has exploited flaws such as Fortra GoAnywhere and BeyondTrust vulnerabilities, and leverages newly announced exploits within 24 hours, sometimes a week before public disclosure. The group uses living-off-the-land techniques, remote monitoring and management software, and RDP for lateral movement, and has been linked to actors including Microsoft-tracked Storm-1175 and North Korean hackers targeting healthcare.
- Victim tally rose from 300+ to 500+ between March 2025 and April 2026
- Access brokers are paid $100 to $1 million; most serve multiple ransomware variants
- Medusa exploits Fortra GoAnywhere and BeyondTrust flaws, using new exploits within 24 hours
- Uses living-off-the-land techniques, RMM software, and RDP for lateral movement
- Healthcare and Public Health sector has been a frequent victim
Full article662 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The updated warning from the FBI, CISA and HHS draws on a year’s worth of investigations to detail how the group gains initial access and what it does afterward.
Listen to this article
0:00
Learn more.
The ransomware-as-a-service group Medusa has adopted fresh tactics to gain access and added hundreds of victims in a little more than a year, according to an updated U.S. government advisory published Tuesday.
The gang is relying on access brokers,compensating them anywhere from $100 to $1 million, with higher prices going to those who work exclusively with Medusa. However, most of the brokers work simultaneously for “multiple variants at the same time,” the advisory from the Cybersecurity and Infrastructure Security Agency, FBI and Health and Human Services Department states in one of the updated portions of the advisory.
Tuesday’s update advisory expands upon aMarch 2025 advisory, drawing on ongoing FBI investigations.nIt includes information on the kinds of software vulnerabilities Medusa has exploited, such as Fortra GoAnywhere and BeyondTrust flaws.
“Medusa actors operate opportunistically by targeting victims with unpatched software rather than focusing on specific organizations or sectors; however, the Healthcare and Public Health (HPH) Sector has been a frequent victim of Medusa operations,” according to the advisory. “Medusa actors leverage newly announced exploits within 24 hours and have been observed to use exploits up to a week before public vulnerability disclosure.’
“However, there is no indication Medusa actors develop their own zero-day or N-day vulnerabilities, preferring instead to obtain advanced access to exploits from unknown sources or to quickly leverage newly announced exploits before potential victims can mitigate vulnerabilities through patching,” the advisory continues.
The approach appears to be netting gains: From March 2025 to April of this year, the victim tally in the advisory jumped from more than 300 to more than 500. The group was first identified in 2021.
“Medusa actors often use legitimate tools and living off the land techniques to evade detection. They may also leverage remote monitoring and management software and remote access services, including Remote Desktop Protocol, for lateral movement,” as updated sections of the advisory detail. “Once inside a network, they use common utilities and tools to support credential access, data exfiltration, and ransomware deployment.”
Earlier this year, Microsoft detailed how a group it dubbed Storm-1175 was making use of Medusa ransomware in speedy operations. Symantec and Carbon Black also detailed earlier this year how North Korean hackers were leaning on Medusa to target the health care sector.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/medusa-ransomware-tactics-cisa-advisory/