Full Report
The updated warning from the FBI, CISA and HHS draws on a year’s worth of investigations to detail how the group gains initial access and what it does afterward. The post Medusa ransomware tallies hundreds of new victims, says updated advisory on group’s tactics appeared first on CyberScoop.
Analysis Summary
# Threat Actor: Medusa
## Attribution & Identity
- **Actor Name:** Medusa
- **Operational Model:** Ransomware-as-a-Service (RaaS).
- **Associated Groups:**
- **Storm-1175:** A group identified by Microsoft as an affiliate utilizing Medusa ransomware in high-tempo operations.
- **Lazarus Group (North Korea):** Linked by Symantec and Carbon Black to the use of Medusa ransomware against specific sectors.
- **Access Brokers:** Medusa frequently employs Initial Access Brokers (IABs), paying between $100 and $1 million for network access.
## Activity Summary
- **Lifespan:** Active since at least 2021.
- **Recent Growth:** Significant increase in operations between March 2025 and April 2026, with the victim count rising from approximately 300 to over 500.
- **Operational Tempo:** The group is known for "high-tempo" operations, often leveraging exploits within 24 hours of a vulnerability being announced (and sometimes up to a week before public disclosure).
## Tactics, Techniques & Procedures
- **Initial Access:** Primarily through the exploitation of unpatched software vulnerabilities and the purchase of access from IABs.
- **Exploitation:** Rapidly leverages N-day vulnerabilities; has recently exploited flaws in **Fortra GoAnywhere** and **BeyondTrust**.
- **Living off the Land (LotL):** Uses legitimate system tools and utilities to blend in with normal network traffic and evade detection.
- **Lateral Movement:** Utilizes Remote Desktop Protocol (RDP) and remote monitoring and management (RMM) software.
- **Persistence & Execution:** Once inside, they deploy common utilities for credential harvesting and data exfiltration before the final ransomware deployment.
- **Vulnerability Acquisition:** Obtains advanced access to exploits from unknown sources rather than developing proprietary zero-days.
## Targeting
- **Sectors:** Primarily opportunistic, but the **Healthcare and Public Health (HPH) Sector** is a frequent and significant target.
- **Geography:** Global (implied by the joint advisory from U.S. agencies including the FBI and CISA).
- **Victims:** Over 500 organizations as of April 2026.
## Tools & Infrastructure
- **Malware:** Medusa Ransomware.
- **Legitimate Software:**
- Remote Desktop Protocol (RDP).
- Remote Monitoring and Management (RMM) software.
- **Vulnerabilities:**
- Fortra GoAnywhere managed file transfer.
- BeyondTrust identity and access management flaws.
## Implications
Medusa represents a highly efficient and opportunistic threat. Their ability to weaponize new vulnerabilities within 24 hours poses a severe challenge to traditional patching cycles. The group’s collaboration with both specialized access brokers and state-sponsored actors (Lazarus) indicates a sophisticated ecosystem that maximizes both financial gain and disruptive potential.
## Mitigations
- **Rapid Patch Management:** Prioritize patching of internet-facing assets within 24 hours of a vulnerability disclosure, specifically for MFT and IAM solutions.
- **RDP Hardening:** Disable unnecessary RDP services, implement MFA, and restrict RDP access through VPNs or gateways.
- **Endpoint Monitoring:** Implement robust EDR/XDR solutions to detect "Living off the Land" techniques and unauthorized use of RMM tools.
- **Third-Party Risk:** Monitor for unusual activity associated with service accounts and management software (e.g., GoAnywhere, BeyondTrust).
- **Credential Protection:** Implement phishing-resistant MFA to mitigate the effectiveness of credentials purchased from access brokers.