โ Medusa¶
Threat-actor battle card ยท maintained from public sources ยท last updated 2026-09-04
Overview¶
Medusa is a ransomware-as-a-service (RaaS) variant first identified in June 2021. It originally operated as a closed ransomware (developers controlled all aspects), then evolved into a partial affiliate model while retaining direct developer control over ransom negotiation โ an unusual structure that distinguishes it from pure RaaS operations and guards against affiliate mismanagement of proceeds. As of February 2025, the FBI, CISA, and MS-ISAC attributed 300+ victims across multiple critical infrastructure sectors in a joint advisory (AA25-071A, March 12, 2025). By early 2026, ransomware.live tracks 517 total victims across 50 countries; the US accounts for 261, followed by UK (38), Canada (36), Italy (14), and Australia (14). Top sectors by victim count: Business Services (97), Healthcare (63), Manufacturing (54), Education (45), Technology (44).
DLS status: The Medusa Blog went dark after the last recorded victim on 2026-02-14. No new postings have appeared on the DLS since then (203+ days as of Sep 4, 2026; confirmed by ransomware.live tracker). No law enforcement takedown or arrests of Medusa/Spearwing operators have been announced. Historical precedent: the group previously went dark Oct 2024โApr 2025 before resurging. Affiliated threat actors operating under the Medusa brand continue to conduct attacks โ see Storm-1175 and Lazarus Group notes below.
August 2026 advisory update: CISA, FBI, and HHS published an updated joint advisory on August 18โ19, 2026 (original: AA25-071A, March 2025), incorporating FBI intelligence through April 2026. Key changes from the March 2025 version: victim count has grown to 500+ critical infrastructure organizations (up from 300+); the updated advisory specifically flags the Healthcare and Public Health sector as primary targeting focus; Medusa affiliates now compensate access brokers between $100 and $1M (higher for exclusivity); zero-day exploitation speed confirmed at within 24 hours of disclosure and in some cases days before public announcement. Healthcare organizations and their billing/technology vendors should consult the updated IOC and ATT&CK TTP lists.
The group operates a dedicated data-leak site ("Medusa Blog") where victims are listed with countdown timers; Medusa also sells a $10,000โ$20,000 "delay fee" that pauses the timer during negotiations. Do not confuse with MedusaLocker, which is a separate, unrelated ransomware family.
Tradecraft¶
- Initial access: Phishing campaigns targeting employee credentials; exploitation of unpatched vulnerabilities (documented: CVE-2024-1709 ScreenConnect auth bypass; Storm-1175 affiliate exploited CVE-2026-23760 SmarterMail zero-day and CVE-2025-10035 GoAnywhere MFT zero-day, in both cases a week before public disclosure). Also purchases access from initial access brokers (IABs) who use phishing to steal VPN and corporate credentials.
- High-velocity dwell: The Storm-1175 affiliate is documented moving from initial access to data exfiltration and ransomware deployment within 24 hours in some intrusions โ an unusually compressed attack timeline.
- Living-off-the-land (LotL): Lateral movement via legitimate remote management tools โ AnyDesk, Atera, ConnectWise, eHorus, N-able, PDQ Deploy, PDQ Inventory, SimpleHelp, Splashtop.
- Defense evasion: Disables security software using PowerShell and batch scripts; uses certutil and PowerShell to disable AV/EDR before encryptor deployment; obfuscates files and information.
- Data exfiltration: Rclone for staged cloud exfiltration; domain credential harvesting for network-wide lateral movement; data exfiltrated before encryption.
- Double extortion: Encrypts victim files; victim name and proof of breach published on Medusa Blog with countdown timer; threatens to sell or release data to multiple buyers if ransom not paid.
- Triple extortion (observed): In at least one confirmed case, an affiliate falsely told a paying victim that the negotiator had stolen the ransom and demanded a second payment for the real decryptor.
- Affiliate model: Developer/operator retains centralized control of negotiations; affiliates conduct intrusions; ransom demands range from $100K to $15M depending on victim size (Storm-1175 affiliate average demand: ~$260,000 in healthcare/nonprofit targets).
Notable victims¶
- University of Mississippi Medical Center (US, healthcare) โ breach disclosed late February 2026; organization experienced a nine-day outage; one of the last confirmed Medusa DLS postings before the Feb 14 dark date
- Minneapolis Public Schools (US, education) โ sensitive student documents for 100,000+ individuals exfiltrated and published
- Municipalities in France (government) โ personal data published on Medusa Blog
- Government agencies in the Philippines
- Technology company created by two of Canada's largest banks
- 300+ critical infrastructure organizations globally as of February 2025 (per CISA AA25-071A); 517+ total victims by early 2026
Nation-state affiliate activity (2026)¶
Storm-1175 (China-linked, April 2026): Microsoft MSTIC identified Storm-1175 as a Medusa RaaS affiliate operating at "high velocity." The actor exploits N-day vulnerabilities and zero-days against web-facing assets, moving from initial access to ransomware deployment in as little as 24 hours. Microsoft confirmed exploitation of at least three zero-day vulnerabilities including CVE-2026-23760 (SmarterMail) and CVE-2025-10035 (GoAnywhere MFT), both exploited a full week before public disclosure. Primary targets: healthcare, education, professional services, and finance in Australia, UK, and US. Microsoft MSTIC Blog
Lazarus Group (DPRK, February 2026): Symantec/Carbon Black Threat Hunter teams identified the North Korea-linked Lazarus Group deploying Medusa ransomware in attacks against at least four healthcare and non-profit organizations in the US since November 2025, and against an unnamed Middle East entity. Average ransom demand in this campaign: $260,000. Lazarus Group's adoption of Medusa โ rather than their own ransomware tooling โ suggests the cost-benefit of paying affiliate fees outweighs developing custom tooling. Activity resembles Andariel sub-group TTPs but has not been formally attributed to a specific Lazarus subgroup. The Register ยท Symantec/Broadcom
Assessment¶
Medusa's DLS has been dark since February 14, 2026, but the platform is not operationally dead: two nation-state-linked actors (China's Storm-1175 and DPRK's Lazarus Group) are confirmed Medusa affiliates as of Q1 2026. The August 18โ19 CISA/FBI/HHS advisory update confirms 500+ victims and signals that the affiliate network's tempo has not declined despite the dark DLS. The centralized-negotiation model that distinguishes Medusa makes it attractive to sophisticated operators who want deniable ransomware capability without building their own infrastructure. The Storm-1175 24-hour attack cycle represents the fastest dwell-to-deploy timeline in tracked RaaS operations. Healthcare is now the explicitly highlighted primary sector per the updated advisory. The combination of Chinese state-linked ransomware-for-profit and DPRK revenue-generation under the same RaaS brand is an unusual and concerning convergence โ treat any Medusa ransom demand as a potential nation-state-adjacent event requiring IR and government notification. CISA/FBI/HHS updated advisory AA25-071A (August 2026 update) provides current IOCs, ATT&CK TTPs, and mitigation guidance.
Sources¶
- CISA/FBI/HHS Updated Advisory AA25-071A โ #StopRansomware: Medusa Ransomware (March 12, 2025; updated August 18, 2026)
- Help Net Security โ Medusa ransomware gang has hit over 500 organizations, CISA warns (August 19, 2026)
- The Record โ More than 200 victims of Medusa ransomware identified over the last year (August 2026)
- CyberScoop โ Medusa ransomware tallies hundreds of new victims, updated advisory (August 2026)
- Microsoft MSTIC โ Storm-1175: Medusa ransomware zero-day affiliate (April 6, 2026)
- The Register โ Lazarus Group targets healthcare orgs with Medusa ransomware (February 24, 2026)
- Symantec/Broadcom โ Medusa ransomware distributed by the Lazarus threat group
- The Hacker News โ Lazarus Group uses Medusa ransomware in Middle East and US healthcare attacks (February 2026)
- CSA Research Note โ Storm-1175: Zero-Day Exploit Chains in Medusa Ransomware Attacks (April 2026)
- Dark Reading โ Storm-1175 deploys Medusa ransomware at high velocity
- ransomware.live โ Medusa group statistics
- The Record โ CISA: More than 300 critical infrastructure orgs attacked by Medusa ransomware
- Picus Security โ Medusa Ransomware Analysis, Simulation, and Mitigation (CISA AA25-071A)
- Dark Reading โ FBI, CISA Raise Alarms As Medusa Ransomware Attacks Grow
- Cybersecurity Dive โ Medusa ransomware slams critical infrastructure organizations
๐๏ธ Attacks & victims¶
All disclosed victims attributed to this actor, newest first.
No attacks recorded yet.