Medusa Ransomware Targets Critical Infrastructure in Escalating RaaS Campaign
The Cybersecurity and Infrastructure Security Agency (CISA), FBI, and Multi-State Information Sharing and Analysis Center (MS-ISAC) have issued a joint advisory (AA25-071A) warning of ongoing Medusa ransomware attacks against critical infrastructure sectors. As of February 2025, the group has compromised over 300 organizations, with confirmed victims spanning healthcare, education, legal services, insurance, technology, and manufacturing.
First detected in June 2021, Medusa initially operated as a closed ransomware group before evolving into a Ransomware-as-a-Service (RaaS) model. Core developers now recruit affiliates while retaining control over ransom negotiations. The group employs a double-extortion tactic, stealing data before encrypting systems and threatening to leak or sell it via a Tor-based site if demands aren’t met. Victims are given 48 hours to respond via Tor chat or the Tox messaging platform, with an option to pay $10,000 in cryptocurrency to delay data leaks by one day.
Medusa’s operations rely heavily on initial access brokers, who are recruited through criminal forums and paid between $100 and $1 million for network access. Phishing and exploitation of known vulnerabilities such as ConnectWise ScreenConnect (CVE-2024-1709) and Fortinet FortiClient EMS (CVE-2023-48788) are primary entry points. Once inside, attackers use living-off-the-land techniques, leveraging PowerShell, cmd.exe, Windows Management Instrumentation, and legitimate tools like AnyDesk, Atera, and ConnectWise for lateral movement. Mimikatz is used to extract credentials, while Rclone facilitates data exfiltration.
The ransomware encryptor, typically named gaze.exe, is deployed via PsExec, PDQ Deploy, or BigFix. Before encryption, it disables security tools, terminates critical services, and deletes volume shadow copies. Files are encrypted with AES-256 and appended with the .medusa extension. In some cases, attackers also target virtual machines to maximize disruption.
Federal agencies recommend immediate patching of internet-facing systems, network segmentation, and monitoring for suspicious activity, including unauthorized use of remote management tools, abnormal PowerShell commands, and attempts to disable endpoint protection. Indicators of compromise (IOCs) include multiple IP addresses and domains linked to command-and-control infrastructure, exfiltration, and backdoor access.
Source: https://cyberpress.org/cisa-warns-of-medusa-ransomware-as-a-service-attacks/
Fortinet cybersecurity rating report: https://www.rankiteo.com/company/fortinet
"id": "FOR1787120638",
"linkid": "fortinet",
"type": "Vulnerability",
"date": "2/2025",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': ['Critical Infrastructure'],
'type': ['Healthcare',
'Education',
'Legal Services',
'Insurance',
'Technology',
'Manufacturing']}],
'attack_vector': ['Phishing',
'Exploitation of known vulnerabilities (CVE-2024-1709, '
'CVE-2023-48788)'],
'data_breach': {'data_encryption': 'Yes (AES-256)',
'data_exfiltration': 'Yes',
'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Personally identifiable '
'information',
'Payment information',
'Sensitive corporate data']},
'date_detected': '2021-06-01',
'date_publicly_disclosed': '2025-02-01',
'description': 'The Cybersecurity and Infrastructure Security Agency (CISA), '
'FBI, and Multi-State Information Sharing and Analysis Center '
'(MS-ISAC) have issued a joint advisory (AA25-071A) warning of '
'ongoing Medusa ransomware attacks against critical '
'infrastructure sectors. As of February 2025, the group has '
'compromised over 300 organizations, with confirmed victims '
'spanning healthcare, education, legal services, insurance, '
'technology, and manufacturing. Medusa employs a '
'double-extortion tactic, stealing data before encrypting '
'systems and threatening to leak or sell it via a Tor-based '
'site if demands aren’t met.',
'impact': {'brand_reputation_impact': 'Yes',
'data_compromised': 'Yes',
'identity_theft_risk': 'Yes',
'operational_impact': 'Disruption of critical services',
'payment_information_risk': 'Yes',
'systems_affected': 'Over 300 organizations'},
'initial_access_broker': {'data_sold_on_dark_web': 'Yes (via Tor-based site)',
'entry_point': ['Phishing',
'Exploitation of known '
'vulnerabilities']},
'investigation_status': 'Ongoing',
'motivation': ['Financial gain', 'Data extortion'],
'post_incident_analysis': {'root_causes': ['Exploitation of unpatched '
'vulnerabilities',
'Use of initial access brokers',
'Living-off-the-land techniques']},
'ransomware': {'data_encryption': 'Yes (AES-256, *.medusa extension)',
'data_exfiltration': 'Yes',
'ransomware_strain': 'Medusa'},
'recommendations': ['Immediate patching of internet-facing systems',
'Network segmentation',
'Monitoring for suspicious activity (unauthorized use of '
'remote management tools, abnormal PowerShell commands, '
'attempts to disable endpoint protection)'],
'references': [{'source': 'CISA, FBI, MS-ISAC Joint Advisory AA25-071A'}],
'response': {'enhanced_monitoring': 'Recommended (for suspicious activity, '
'unauthorized use of remote management '
'tools, abnormal PowerShell commands)',
'law_enforcement_notified': 'Yes (CISA, FBI, MS-ISAC)',
'network_segmentation': 'Recommended',
'remediation_measures': ['Immediate patching of internet-facing '
'systems',
'Network segmentation']},
'threat_actor': 'Medusa Ransomware Group',
'title': 'Medusa Ransomware Targets Critical Infrastructure in Escalating '
'RaaS Campaign',
'type': 'Ransomware',
'vulnerability_exploited': ['CVE-2024-1709 (ConnectWise ScreenConnect)',
'CVE-2023-48788 (Fortinet FortiClient EMS)']}