Target Industry
Medusa ransomware is targeting the private and public sectors in healthcare, education, legal, insurance, technology, and manufacturing.
Overview
The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and Multi-State Information Sharing and Analysis Centre (MS-ISAC) have issued a joint advisory warning organisations about the ongoing threat of Medusa ransomware. This ransomware operates as a Ransomware-as-a-Service (RaaS) model and was first identified in June 2021.
Impact
Since February 2025, Medusa ransomware has impacted over 300 victims in various sectors across the United States. Medusa ransomware employs double extortion tactics with some organisations being subjected to triple extortion. This tactic not only encrypts data but also steals it, threatening to publish sensitive information if the ransom is not paid. This can severely disrupt business operations, leading to significant downtime and reputational damage. Affected organisations may lose the trust of customers and partners, further exacerbating the impact.
Exploitation
Medusa ransomware uses brute-force attacks to target weak passwords on systems like RDP and VPN, exploits software vulnerabilities, and employs phishing to gain access. It utilises Living off the Land (LotL) techniques, using legitimate tools like ConnectWise and PDQ Deploy to avoid detection and spread ransomware. Medusa employs AES-256 and RSA-2048 encryption algorithms to ensure data is securely encrypted. During encryption, it skips certain files to maintain system stability.
The ransomware has also been known to exploit the following vulnerabilities:
- CVE-2022-2294 (CVSS Score 8.8): A heap buffer overflow vulnerability in WebRTC
- CVE-2022-2295 (CVSS Score 8.8): A type confusion vulnerability in Google Chrome’s V8 engine that allows remote code execution
- CVE-2024-1709 (CVSS Score 10.0): A critical vulnerability allowing remote code execution due to improper input validation in ConnectWise ScreenConnect
- CVE-2023-48788 (CVSS Score 9.8): A critical SQL injection vulnerability in Fortinet’s FortiClient EMS software.
Containment, Mitigations & Remediations
To mitigate ransomware threats, it’s essential to implement strong security measures on all endpoints by disabling unnecessary services and applying the latest security patches. Protect credentials by using multi-factor authentication (MFA) and limiting the use of privileged accounts.
To mitigate against the ongoing risk posed by ransomware, please refer to the industry standard defensive recommendations outlined by CISA.
Indicators of Compromise
The ransomware includes several key Indicators of Compromise (IoCs). For the current IoCs, please refer to Darktrace, RasomwareLive, and RansomLook.
Threat Group
Medusa ransomware, a cybercriminal group that emerged in June 2021, is known for sophisticated attacks and multi-extortion tactics targeting industries like healthcare, manufacturing, education, and high technology. The group exploits vulnerabilities in internet-facing assets, hijacks legitimate accounts, and uses techniques like living-off-the-land (LotL) to evade detection. Medusa operates a data leak site (Medusa’s Blog) on the dark web, uses Telegram for communication and ransom negotiations, and maintains a facade called “OSINT Without Borders” to promote its activities and identify targets.
Tactics, Techniques, and Procedures
- T1566: Phishing
- T1566.001: Spearphishing Attachment
- T1566.002: Spearphishing Link
- T1569.002: System Services: Service Execution
- T1021.001: Remote Services: Remote Desktop Protocol
- T1110: Brute Force
- T1485: Data Destruction
Further Information













