CISA Warns: Medusa Ransomware Steals Data, Disables Security, Encrypts Networks
Key Takeaways The Medusa ransomware group is actively compromising critical infrastructure sectors, including healthcare, education, and manufacturing. Attackers disable security tools, exfiltrate...
Key Takeaways
- The Medusa ransomware group is actively compromising critical infrastructure sectors, including healthcare, education, and manufacturing.
- Attackers disable security tools, exfiltrate sensitive data, and encrypt entire networks using a double-extortion model.
- Initial access often involves exploiting known vulnerabilities in software like ScreenConnect, Fortinet FortiClient EMS, and Fortra GoAnywhere MFT, as well as a newly identified BeyondTrust flaw (CVE-2026-1731).
- Over 500 organizations have been confirmed victims, with the healthcare sector disproportionately affected.
- Federal agencies urge immediate patching, network segmentation, and robust multi-factor authentication to mitigate risks.
The Cybersecurity and Infrastructure Security Agency (CISA), in collaboration with the Federal Bureau of Investigation (FBI) and the U.S. Department of Health and Human Services (HHS), has issued an urgent cybersecurity advisory. This updated warning highlights the ongoing and aggressive campaigns by Medusa ransomware actors, who are actively breaching enterprise networks, neutralizing security defenses, stealing confidential information, and encrypting systems.
Table Of Content
The revised alert, designated AA25-071A, incorporates forensic intelligence gathered through April 2026. This data confirms that Medusa has successfully attacked over 500 organizations across various critical infrastructure sectors. These sectors include vital areas such as healthcare, education, legal services, insurance, manufacturing, and technology.
Medusa Ransomware: A Deep Dive into its Operations
Medusa, which first emerged as a clandestine malware operation in June 2021, transitioned to a Ransomware-as-a-Service (RaaS) model around 2023. This operational shift allows the group’s core developers to lease their ransomware payloads to a network of affiliates. In return, these affiliates share a portion of the extortion proceeds with the developers.
The criminal syndicate employs a sophisticated double-extortion strategy. This involves first exfiltrating valuable data, such as intellectual property and patient records, before proceeding to encrypt the victim’s systems. The stolen data is then published on a dedicated dark web leak site if ransom demands are not met.
HHS joined the advisory as a co-author due to Medusa’s persistent targeting of hospitals and public health organizations. These entities continue to face severe operational disruptions from the ransomware group’s campaigns.
Initial Access and Exploitation
Medusa affiliates typically gain their initial network access through collaborations with Initial Access Brokers (IABs). These brokers sell valid corporate access credentials, with payouts ranging from $100 to an astounding $1 million.
The threat actors also actively exploit known software vulnerabilities. These include the ScreenConnect authentication bypass (CVE-2024-1709), a SQL injection vulnerability in Fortinet FortiClient EMS (CVE-2023-48788), deserialization flaws in Fortra GoAnywhere MFT, and a recently discovered remote code execution vulnerability in BeyondTrust, tracked as CVE-2026-1731.
As detailed in the joint security bulletin from CISA and Federal Partners, Medusa operators are known to weaponize public vulnerabilities within 24 hours of their disclosure, and sometimes even before patches are publicly available. This rapid exploitation necessitates extremely fast patching cycles for critical endpoints.
Post-Compromise Tactics and Tools
Once inside a network, Medusa operators heavily rely on “living-off-the-land” techniques. They leverage legitimate Windows binaries like PowerShell cmd.exe and Windows Management Instrumentation (WMI) to map internal infrastructure discreetly, avoiding detection by standard alerts.
Adversaries deploy compromised or stolen kernel drivers to disable endpoint detection and response (EDR) software, extract cached credentials from LSASS memory, and misuse legitimate remote monitoring and management (RMM) platforms such as AnyDesk, Atera, and SimpleHelp. These methods reflect a broader trend among ransomware groups to neutralize security software before initiating encryption.
Furthermore, Medusa actors employ tools like Mimikatz, CrackMapExec, and Rclone to harvest network secrets and facilitate large-scale file exfiltration. They weaponize administrative utilities, camouflaging malicious commands as routine system maintenance activities.
The Windows encryption payload, named gaze.exe, is designed to systematically halt security services, delete volume shadow copies, and terminate database management systems. It then encrypts files with the .medusa extension using robust AES-256 algorithms.
Victims are typically given 48 hours to begin negotiations via Tor-based live chat portals or Tox messenger channels. The syndicate frequently offers temporary discounts for prompt payments, while threatening to auction off stolen corporate datasets if deadlines are not met.
What You Should Do
- Prioritize Patching: Immediately apply security updates for all software, especially those addressing vulnerabilities like CVE-2024-1709, CVE-2023-48788, and CVE-2026-1731.
- Implement Network Segmentation: Segment internal subnets to limit lateral movement of attackers within the network.
- Restrict Remote Management Services: Strictly limit inbound remote management services and secure them with strong controls.
- Enforce Phishing-Resistant MFA: Deploy and enforce multi-factor authentication (MFA) that is resistant to phishing attacks across all accounts.
- Maintain Immutable Backups: Ensure critical data is backed up regularly to immutable, offline storage, making it inaccessible to ransomware.
- Audit Endpoint Telemetry: Continuously monitor and audit endpoint telemetry for any unauthorized RMM installations or anomalous execution of administrative tools.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.