Medusa Ransomware Attack: CISA Issues Urgent Warning

CISA warns Medusa ransomware actively hits multiple sectors and exploits widely used tools

Medusa ransomware is once again posing a major threat to organisations, as confirmed by a recent joint advisory from CISA, FBI and HHS. Medusa ransomware affiliates are actively breaching networks, stealing sensitive data and disabling security tools, impacting over 500 organisations across healthcare, education, legal, insurance, manufacturing and technology. This post examines the specifics of the latest attacks, how the ransomware operates, which vulnerabilities are being exploited and the current status of exploitation.

Medusa Ransomware: Targeted Sectors and Attack Timeline

Medusa ransomware was first identified in June 2021 as a closed operation. By 2023, the threat group had shifted to a Ransomware-as-a-Service (RaaS) model, leasing its malware to affiliates in return for a share of the profits. As of April 2026, forensic analysis has confirmed that Medusa has compromised more than 500 organisations across a range of critical infrastructure sectors.

  • Healthcare: Hospitals and public health organisations are being disproportionately targeted.
  • Education: Schools, colleges and universities have faced significant impact.
  • Legal and Insurance: Law firms and insurance companies are among the victims.
  • Manufacturing and Technology: Businesses in these sectors are also being successfully attacked.

The joint CISA, FBI and HHS advisory (AA25-071A) reflects the growing scale and sophistication of Medusa’s campaign. The group’s operations are not limited to the US, with reported compromises spanning multiple countries and continents.

How Medusa Ransomware Gains Access and Spreads

Medusa ransomware affiliates use a variety of methods to gain initial access to target networks. The group collaborates closely with underground Initial Access Brokers (IABs), who sell valid corporate access credentials for sums ranging from $100 to $1 million, depending on the organisation’s profile. Once access is obtained, Medusa affiliates rapidly exploit newly disclosed vulnerabilities in widely used enterprise software.

Exploited Vulnerabilities and Attack Techniques

  • ScreenConnect (CVE-2024-1709): An authentication bypass vulnerability that allows attackers remote access to vulnerable systems.
  • FortiClient EMS (CVE-2023-48788): A SQL injection flaw used to compromise Fortinet management consoles.
  • Fortra GoAnywhere MFT: Deserialization vulnerabilities allow remote code execution and data exfiltration.
  • BeyondTrust RCE (CVE-2026-1731): A newly identified remote code execution vulnerability actively targeted before public patches were available.

According to the advisory, Medusa operators are able to weaponise public vulnerabilities within 24 hours of disclosure, and in some cases, they exploit flaws before patches are released. This rapid exploitation cycle means that organisations with delayed patching processes are especially vulnerable.

Attack Workflow: Disabling Defences and Double Extortion

Once inside a network, Medusa ransomware affiliates use a combination of native Windows tools and third-party utilities to map infrastructure, move laterally and avoid detection. Living-off-the-land techniques are central to their strategy, relying on tools like PowerShell, cmd.exe, and Windows Management Instrumentation (WMI). These methods help attackers blend in with legitimate administrative activity.

Disabling Security and Exfiltrating Data

  • Deploying or abusing vulnerable and stolen kernel drivers to terminate endpoint detection and response (EDR) software.
  • Dumping cached credentials from LSASS memory to escalate privileges.
  • Abusing legitimate remote monitoring and management (RMM) platforms such as AnyDesk, Atera and SimpleHelp to maintain persistence and control.
  • Using tools like Mimikatz, CrackMapExec and Rclone for harvesting credentials and staging bulk file exfiltration.

After exfiltrating valuable data, Medusa ransomware affiliates encrypt target systems and issue ransom demands. If payment is not made, stolen data is published on a dedicated dark web leak portal, increasing pressure on victims. The group’s double-extortion approach amplifies the damage, combining operational disruption with the risk of data exposure.

Current Exploitation Status and Observed Trends

The Medusa ransomware campaign is ongoing and highly active. The group’s ability to exploit vulnerabilities within hours of public disclosure has been repeatedly observed, particularly with high-profile flaws in ScreenConnect, FortiClient EMS and BeyondTrust solutions. Healthcare and public health entities remain the most targeted, although all sectors using vulnerable software are at risk.

Key trends identified in the advisory include:

  • Accelerated exploitation timelines for newly disclosed vulnerabilities.
  • Increased use of RMM tools and living-off-the-land binaries to bypass traditional security controls.
  • Routine disabling of EDR solutions as part of the initial compromise workflow.
  • Widespread credential theft and lateral movement within victim environments.

With more than 500 organisations already affected and the attack infrastructure continuing to evolve, Medusa ransomware remains a critical threat for enterprises of all sizes.

Why This Matters and What Organisations Should Do

The Medusa ransomware campaign demonstrates the ongoing risks posed by sophisticated RaaS groups who rapidly exploit public vulnerabilities. Sectors holding sensitive data, such as healthcare and education, face disproportionate risks due to the operational impact of data exfiltration and system encryption.

  • Immediate patching of vulnerabilities cited in the CISA advisory is essential.
  • Review and monitor for unusual use of administrative tools and RMM platforms.
  • Ensure endpoint protection cannot be easily disabled by unauthorised users.

Organisations should focus on the specific vulnerabilities and attack methods highlighted in this campaign to reduce exposure and strengthen detection and response capabilities.

Originally reported by cybersecuritynews.com.

Share this bulletin

About the Author

Headshot of Jonny Pelter, leading cyber security expert in the UK and CISO

Jonny Pelter

Partner

  • CIPM
  • CIPP/E
  • CISSP
  • CISM
  • CRISC
  • ISO27001
  • Prince2
  • MSc
  • BSc

Jonny Pelter

Jonny is a Founding Partner at CyPro and executive group level CISO who has worked closely with the British intelligence agencies NCSC and GCHQ.

An ex-professional rugby player and originating from KPMG and Deloitte, Jonny has a wealth of experience across numerous sectors including technology, critical national infrastructure, financial services, oil & gas, insurance, betting, pharmaceuticals and utilities.

Jonny is a leading cyber security expert in the UK, having featured on national media for his professional commentary such as BBC News, iPlayer, Telegraph and Times Radio.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call