ZeroHour
Help Net Securitypublished ()ingested @helpnetsecurity

Medusa ransomware gang has hit over 500 organizations, CISA warns

highRansomware exploited in the wildimportance 75
AI summary · glm-5.3-flash

FBI, CISA, and HHS warn Medusa ransomware has hit over 500 organizations across critical infrastructure since June 2021, using phishing and unpatched flaws.

An updated joint advisory from CISA, FBI, and HHS states Medusa ransomware has affected more than 500 organizations, spanning healthcare, defense, manufacturing, government, IT, financial services, education, insurance, and legal sectors. Since early 2023 Medusa has operated a ransomware-as-a-service affiliate model and buys access from initial access brokers for $100 to $1 million. Affiliates gain entry via phishing and unpatched internet-facing software, exploiting newly disclosed flaws in ScreenConnect, Fortinet EMS, Fortra GoAnywhere, and BeyondTrust within 24 hours. The group runs double extortion, giving victims 48 hours before leak-site publication, with $10,000 in cryptocurrency buying a one-day delay.

  • Joint CISA/FBI/HHS advisory update covers 500+ Medusa victims since June 2021, including healthcare, defense, manufacturing, and finance.
  • Medusa moved to a RaaS affiliate model in early 2023 and buys access from brokers for $100 to $1 million.
  • Affiliates exploit newly disclosed flaws in ScreenConnect, Fortinet EMS, GoAnywhere, and BeyondTrust within 24 hours.
  • Uses PowerShell, Mimikatz, AnyDesk; gaze.exe encrypts files with .medusa extension after stopping backup and security services.
  • Double extortion: 48-hour deadline, leak-site countdown; $10,000 in crypto buys a one-day extension.
Full article403 words · extracted from helpnetsecurity.com · click to collapse

Medusa ransomware has breached more than 500 organizations since it first appeared in June 2021, the FBI, CISA, and the Department of Health and Human Services (HHS) said in an updated joint advisory.

Medusa ransomware

The update builds on an advisory first issued in March 2025 and draws on FBI investigations conducted as late as April 2026.

“Medusa developers and affiliates have impacted over 500 victims from a variety of critical infrastructure sectors,” the advisory reads, listing healthcare, defense, manufacturing, government services, IT, and financial services among those hit. Victims outside those sectors span education, insurance, and law firms.

“Medusa originally operated as a closed ransomware operation, meaning the same group of cyber threat actors controlled all development and associated ransomware campaigns. Since at least early 2023, Medusa progressed to using an affiliate model, selling RaaS to affiliates who are granted varying levels of trust based upon experience and profitability,” they said.

The gang buys access from initial access brokers on cybercriminal forums, paying between $100 and $1 million, and most of those brokers aren’t exclusive to Medusa. “Most IABs, however, appear to be willing to work for multiple variants at the same time,” the advisory states.

Medusa relies on common techniques, phishing to steal credentials and unpatched software to gain access. The advisory names flaws in ScreenConnect, Fortinet EMS, Fortra GoAnywhere, and BeyondTrust as recent targets, and notes that affiliates move fast once a vulnerability goes public.

“Medusa actors leverage newly announced exploits within 24 hours,” the advisory notes, adding that there’s no sign the group develops its own zero-days.

Once inside, the group leans on tools already present on a network rather than custom malware, among them PowerShell, Mimikatz for stealing credentials, and remote access software like AnyDesk and SimpleHelp. A process called gaze.exe handles the encryption itself, shutting down backup and security services before locking files with a .medusa extension.

Medusa follows a double-extortion model. According to the agencies, victims get 48 hours to respond to a ransom note before Medusa starts contacting them directly, and their stolen data goes up on a leak site with a countdown timer. Paying $10,000 in cryptocurrency buys another day.

The agencies recommend patching internet-facing systems, segmenting networks to limit lateral movement, and blocking untrusted traffic from reaching remote access services. They continue to discourage paying ransoms, and encourage victims to report incidents to the FBI’s Internet Crime Complaint Center or CISA.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/08/19/medusa-ransomware-cisa-warning/