Secure Bulletin Navigating the cyber sea with knowledge
Home > Articolo > CISA Sounds Alarm on Medusa Ransomware After 500+ Critical Infrastructure Hits
CISA Sounds Alarm on Medusa Ransomware After 500+ Critical Infrastructure Hits
Read Time:3 Minute, 37 Second

U.S. federal agencies have renewed their warning about Medusa, a ransomware-as-a-service (RaaS) operation that has quietly become one of the most prolific extortion crews targeting critical infrastructure. In an updated joint advisory, the Cybersecurity and Infrastructure Security Agency (CISA), the FBI, and the Department of Health and Human Services (HHS) confirmed that the group has now compromised more than 500 organizations across sectors including healthcare, education, legal services, insurance, and manufacturing.

From Closed Crew to Affiliate-Driven Operation

Medusa first surfaced around mid-2021 as a tightly controlled operation, but by 2023 its developers had pivoted to a franchise model, recruiting affiliates and initial access brokers (IABs) to scale attacks. According to the advisory, brokers can earn anywhere from $100 to as much as $1 million for handing over valid corporate credentials, giving the core group a steady pipeline into new victim networks without having to do the initial legwork themselves.

That affiliate structure appears to be paying off. Investigators estimate average ransom payments hover around $260,000, but the group has pushed demands as high as $15 million in some cases, using a familiar double-extortion playbook: steal sensitive data first, then encrypt it, and threaten to leak everything if the victim doesn’t pay within a tight window — typically 48 hours before the group begins pressuring for a decision.

Speed Is the Weapon

What sets Medusa apart from many of its ransomware peers is velocity. The advisory notes that affiliates have been observed weaponizing newly disclosed vulnerabilities within 24 hours of publication — occasionally before a patch is even available. Flaws that have already been pulled into Medusa’s toolkit include the ScreenConnect authentication bypass (CVE-2024-1709), a SQL injection bug in Fortinet’s FortiClient EMS (CVE-2023-48788), deserialization issues in Fortra’s GoAnywhere MFT, and a more recent remote code execution flaw in BeyondTrust software (CVE-2026-1731).

Once inside a network, affiliates lean heavily on living-off-the-land techniques, using built-in tools like PowerShell, cmd.exe, and Windows Management Instrumentation to blend in with normal administrative activity. To neutralize endpoint defenses, the group has also deployed vulnerable or stolen kernel drivers capable of terminating EDR agents — a technique sometimes called “bring your own vulnerable driver.”

Harvesting Credentials and Moving Data

Credential theft is central to the operation. Investigators say affiliates routinely dump credentials from LSASS memory and abuse legitimate remote monitoring and management (RMM) platforms — including AnyDesk, Atera, and SimpleHelp — to maintain persistent, low-visibility access. Tools like Mimikatz and CrackMapExec support lateral movement, while Rclone is used to exfiltrate stolen files to attacker-controlled infrastructure before the final encryption stage.

The encryption payload itself, compiled as an executable often labeled gaze.exe, is engineered to first stop database and backup services, minimizing the odds that a victim can quietly restore from local backups before negotiations even start. Files are locked using AES-256 encryption and appended with the .medusa extension. Negotiations then move to dedicated Tor-based chat portals or encrypted Tox messaging, where the group offers payment discounts for speed and threatens to auction stolen data publicly if deadlines slip.

What Defenders Should Do Now

CISA’s guidance for organizations, particularly those in critical infrastructure sectors, centers on cutting off the access points Medusa affiliates rely on most:

  • Patch known, actively exploited vulnerabilities immediately rather than waiting for a routine cycle
  • Segment internal networks to limit how far an intruder can move laterally after an initial foothold
  • Restrict or tightly monitor inbound remote management services and unauthorized RMM installations
  • Require phishing-resistant multi-factor authentication across remote access and privileged accounts
  • Keep offline, immutable backups that cannot be reached or altered by an attacker already inside the network
  • Watch endpoint telemetry for unusual PowerShell, WMI, or administrative tool activity that could signal early-stage intrusion

The advisory also includes an extensive list of indicators of compromise — IP addresses, domains, and known payload delivery URLs — that security teams can feed into SIEM platforms and threat intelligence tools to hunt for early signs of Medusa activity inside their own environments.

With affiliates now moving from vulnerability disclosure to active exploitation in less than a day, the advisory’s core message is blunt: organizations that treat patching as a monthly chore rather than an urgent, continuous process are the ones most likely to end up on Medusa’s growing victim list.

Share: Twitter  |  Facebook  |  LinkedIn
Join the discussion

This is a blog in the Fediverse: you can find this article everywhere with @blog@securebulletin.com and every comment/answer will appear here.

If you want to comment on CISA Sounds Alarm on Medusa Ransomware After 500+ Critical Infrastructure Hits, use the discussion on Forum.

>> forum community

Comments

Leave a Reply