Medusa Ransomware is a ransomware-as-a-service threat that has targeted organizations across multiple critical-infrastructure sectors, including medical, education, legal, insurance, technology, and manufacturing. In March 2025, the FBI, CISA, and MS-ISAC issued a joint advisory detailing the tactics, techniques, procedures, and indicators associated with Medusa activity identified through FBI investigations as recently as February 2025.

According to the advisory, Medusa has been active since 2021 and had impacted more than 300 victims by February 2025. The group uses a double-extortion model: attackers encrypt victim data while also threatening to publish exfiltrated information if a ransom is not paid. That combination can create both operational disruption and significant legal, privacy, and reputational pressure.

What Is Medusa Ransomware?

Medusa Ransomware is a ransomware-as-a-service operation. In a RaaS model, the developers maintain the ransomware operation while affiliates or access brokers help identify or compromise victims. The FBI, CISA, and MS-ISAC advisory notes that Medusa originally operated as a more closed ransomware group but later adopted an affiliate model while retaining centralized control over important functions such as ransom negotiation.

The advisory also distinguishes Medusa Ransomware from MedusaLocker ransomware and from malware using the Medusa name in the mobile ecosystem. That distinction matters because similarly named threats can lead to confusion during investigation, threat hunting, and response.

Organizations can review the full joint advisory here: #StopRansomware: Medusa Ransomware.

How Medusa Ransomware Gets Initial Access

The joint advisory says Medusa actors commonly rely on two broad paths for initial access: stolen credentials obtained through phishing and exploitation of vulnerable internet-facing systems. The advisory specifically references exploitation of vulnerabilities including CVE-2024-1709 in ConnectWise ScreenConnect and CVE-2023-48788 affecting Fortinet EMS.

This reinforces a familiar ransomware pattern. Attackers do not always need highly sophisticated zero-day exploits. They can often succeed through exposed remote-access systems, delayed patching, weak credentials, reused passwords, or a user who responds to a convincing phishing message.

For defenders, that means ransomware prevention is not one control. It requires a combination of external visibility, vulnerability management, strong identity controls, user-risk reduction, and continuous monitoring.

What Medusa Actors Do After They Get In

Once inside an environment, Medusa actors have been observed using legitimate administrative and network tools to understand the victim environment and move toward valuable systems. The advisory describes use of tools such as Advanced IP Scanner and SoftPerfect Network Scanner, along with PowerShell, Windows Command Prompt, and Windows Management Instrumentation.

This type of “living off the land” activity can be difficult to detect because many of the same utilities are used by legitimate administrators. The difference is context: who launched the command, where it originated, what systems were queried, what happened next, and whether the activity fits normal administrative behavior.

Medusa actors have also been observed scanning common services and remote-access ports, deleting PowerShell command history, obfuscating commands, using remote-management tools, disabling services, and attempting to interfere with backup and recovery functions.

Why Medusa Ransomware Creates More Than an Availability Problem

Ransomware is often described as an encryption problem, but Medusa Ransomware is also an extortion and data-exposure problem. The double-extortion model means an organization may have to investigate not only which systems were encrypted, but also which data may have been accessed, staged, or removed before encryption occurred.

That distinction has practical consequences. Recovery from backups does not answer whether sensitive information was exfiltrated. A technically restored network may still require forensic investigation, legal review, regulatory assessment, customer notification analysis, and ongoing monitoring for leaked information.

For organizations in legal, healthcare, insurance, education, technology, or manufacturing, the operational consequences can be especially significant because ransomware can affect confidential data, regulated information, production systems, service delivery, and critical business relationships.

Medusa Ransomware: Controls Organizations Should Prioritize

The FBI, CISA, and MS-ISAC provide a broad set of mitigations in the joint advisory. The highest-value actions are familiar because they address common ransomware entry points and lateral-movement paths.

  • Patch internet-facing systems. Prioritize known exploited vulnerabilities and externally accessible services rather than relying only on general patch cycles.
  • Require multi-factor authentication. MFA should be used wherever possible, especially for VPNs, webmail, remote access, and privileged accounts.
  • Segment networks. Limit unnecessary traffic between systems and reduce an attacker’s ability to move laterally after the first compromise.
  • Maintain resilient backups. Backups should be offline or otherwise protected, regularly tested, and designed so attackers cannot easily modify or delete them.
  • Review privileged and unknown accounts. Investigate newly created, unexpected, or dormant accounts across Active Directory, servers, and administrative platforms.
  • Monitor command-line and scripting activity. PowerShell, command-line tools, remote-management software, and administrative utilities should be monitored in context.
  • Reduce unnecessary remote exposure. Disable unused ports and services and restrict remote access to trusted sources where possible.

Detection Matters Because Medusa Uses Legitimate Tools

A mature security program should not assume that malware will always look obviously malicious. The Medusa advisory is a good example of why behavior matters. Legitimate tools such as PowerShell, WMI, remote desktop, network scanners, and system utilities can become part of an attack chain when used by the wrong account, from the wrong host, at the wrong time.

Cyber Defense and Managed Detection and Response can help organizations correlate endpoint, identity, network, cloud, and threat-intelligence signals so suspicious administrative activity receives context before an incident reaches the encryption stage.

Vulnerability Management and Attack Surface Management are equally important because the fastest ransomware response is preventing exposed vulnerabilities and remote services from becoming the initial entry point.

If Medusa Ransomware Is Already in the Environment

If an organization suspects active Medusa Ransomware activity, the priority shifts from prevention to containment, evidence preservation, scoping, and recovery. Systems may need to be isolated, but actions should be coordinated carefully so defenders do not destroy evidence or lose visibility into attacker activity.

Digital Forensics and Incident Response can help establish the initial access path, identify affected systems and accounts, determine whether data was exfiltrated, preserve evidence, support containment, and build a defensible incident timeline.

The FBI, CISA, and MS-ISAC do not encourage paying ransoms because payment does not guarantee recovery and may encourage continued criminal activity. They also urge organizations to report ransomware incidents even if the organization ultimately decides not to pay.

Medusa Ransomware Is a Reminder to Test the Whole Program

The most important lesson from Medusa Ransomware is not a single indicator, tool, or vulnerability. It is the way ransomware attacks move across security domains: phishing and external exposure can create initial access; identity weakness can enable privilege escalation; legitimate tools can support discovery and lateral movement; weak segmentation can increase blast radius; and inadequate backup protection can turn compromise into prolonged operational disruption.

Organizations should therefore test controls as a system. Can security teams detect suspicious PowerShell? Can they identify unexpected administrative accounts? Are backups protected from the same credentials used in production? Are internet-facing systems patched quickly enough? Does the incident-response team know who has authority to isolate critical systems?

Ransomware resilience comes from reducing the number of easy entry points, detecting abnormal behavior early, limiting attacker movement, preserving recovery options, and knowing what to do when prevention fails.

Medusa Ransomware has impacted hundreds of organizations across critical sectors. Learn how the operation gains access, moves through networks, and what defenders should prioritize.

VT
AUTHOR

Velocis Technologies

Managed security operations and licensed investigations, based in Frisco, Texas.