Medusa Ransomware Surges: CISA, FBI, and HHS Issue Joint Warning on Double-Extortion Attacks
A joint advisory from the Cybersecurity and Infrastructure Security Agency (CISA), FBI, and U.S. Department of Health and Human Services (HHS) warns of escalating attacks by the Medusa ransomware group, which has compromised over 500 organizations across critical infrastructure sectors including healthcare, education, legal, and manufacturing through April 2026.
First detected in June 2021, Medusa transitioned to a Ransomware-as-a-Service (RaaS) model in 2023, enabling affiliates to deploy its payloads in exchange for a share of extortion profits. The group employs a double-extortion scheme, exfiltrating sensitive data before encrypting systems and leaking stolen files on a dedicated dark web portal. Healthcare providers remain a primary target, prompting HHS’s involvement in the advisory.
Initial Access & Exploitation
Medusa affiliates gain entry via stolen credentials purchased from Initial Access Brokers (IABs), with payouts ranging from $100 to $1 million. They also exploit known vulnerabilities, including:
- ScreenConnect (CVE-2024-1709)
- Fortinet FortiClient EMS (CVE-2023-48788)
- BeyondTrust (CVE-2026-1731)
- Fortra GoAnywhere MFT flaws
Operators weaponize vulnerabilities within 24 hours of disclosure, sometimes before patches are available, underscoring the need for rapid remediation.
Post-Compromise Tactics
Once inside a network, attackers use living-off-the-land techniques, leveraging native tools like PowerShell, WMI, and cmd.exe to evade detection. They deploy vulnerable kernel drivers to disable endpoint detection and response (EDR) software, dump credentials via LSASS memory, and abuse remote monitoring tools (AnyDesk, Atera, SimpleHelp). Additional tools like Mimikatz, CrackMapExec, and Rclone facilitate lateral movement and data exfiltration.
Encryption & Extortion
The ransomware payload (gaze.exe) terminates security services, deletes volume shadow copies, and encrypts files with AES-256, appending the .medusa extension. Victims are given 48 hours to negotiate via Tor-based chat or Tox messenger, with ransom demands reaching $15 million (average payouts near $260,000). Missed deadlines trigger threats to auction stolen data.
Indicators of Compromise (IoCs)
Federal agencies shared multiple IoCs, including IP addresses linked to PHP web shells, Ligolo proxy tools, and BeyondTrust exploitation, as well as URLs used to deliver malicious payloads. Security teams are advised to monitor for unauthorized RMM tool installations and anomalous administrative activity.
The advisory emphasizes immediate patching, network segmentation, and phishing-resistant multifactor authentication to mitigate risks.
Source: https://cybersecuritynews.com/medusa-ransomware/
Fortinet cybersecurity rating report: https://www.rankiteo.com/company/fortinet
"id": "FOR1787077462",
"linkid": "fortinet",
"type": "Vulnerability",
"date": "4/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': ['Healthcare',
'Education',
'Legal',
'Manufacturing'],
'type': 'Organization'}],
'attack_vector': ['Stolen credentials',
'Exploitation of known vulnerabilities'],
'data_breach': {'data_encryption': True,
'data_exfiltration': True,
'personally_identifiable_information': True,
'sensitivity_of_data': 'High (PII, healthcare data)',
'type_of_data_compromised': 'Sensitive data'},
'date_detected': '2021-06-01',
'description': 'A joint advisory from CISA, FBI, and HHS warns of escalating '
'attacks by the Medusa ransomware group, which has compromised '
'over 500 organizations across critical infrastructure sectors '
'including healthcare, education, legal, and manufacturing '
'through April 2026. The group employs a double-extortion '
'scheme, exfiltrating sensitive data before encrypting systems '
'and leaking stolen files on a dedicated dark web portal.',
'impact': {'data_compromised': 'Sensitive data exfiltrated',
'identity_theft_risk': 'High (PII exposure)',
'operational_impact': 'Encrypted systems, disrupted operations',
'systems_affected': 'Over 500 organizations'},
'initial_access_broker': {'entry_point': 'Stolen credentials (purchased from '
'IABs)'},
'investigation_status': 'Ongoing',
'motivation': ['Financial gain', 'Data extortion'],
'post_incident_analysis': {'corrective_actions': ['Patch management',
'Credential hygiene',
'EDR/XDR deployment'],
'root_causes': ['Exploitation of unpatched '
'vulnerabilities',
'Use of stolen credentials',
'Living-off-the-land techniques']},
'ransomware': {'data_encryption': True,
'data_exfiltration': True,
'ransom_demanded': 'Up to $15 million (average $260,000)',
'ransomware_strain': 'Medusa'},
'recommendations': ['Immediate patching of vulnerabilities',
'Network segmentation',
'Phishing-resistant multifactor authentication',
'Monitor for unauthorized RMM tool installations',
'Anomalous administrative activity detection'],
'references': [{'source': 'CISA, FBI, HHS Joint Advisory'}],
'regulatory_compliance': {'regulatory_notifications': 'CISA, FBI, HHS '
'advisory'},
'response': {'enhanced_monitoring': 'Recommended',
'law_enforcement_notified': 'CISA, FBI, HHS',
'network_segmentation': 'Recommended',
'remediation_measures': ['Immediate patching',
'Network segmentation',
'Phishing-resistant MFA']},
'stakeholder_advisories': 'CISA, FBI, HHS advisory issued',
'threat_actor': 'Medusa ransomware group',
'title': 'Medusa Ransomware Surges: Double-Extortion Attacks Targeting '
'Critical Infrastructure',
'type': 'Ransomware',
'vulnerability_exploited': ['CVE-2024-1709 (ScreenConnect)',
'CVE-2023-48788 (Fortinet FortiClient EMS)',
'CVE-2026-1731 (BeyondTrust)',
'Fortra GoAnywhere MFT flaws']}