Medusa Ransomware Gang Identified with Over 200 Victims in Last Year
Federal cybersecurity agencies have warned that the Medusa ransomware gang has been identified with over 200 victims in the last year, with the group focusing its efforts on the healthcare sector. The Cybersecurity and Infrastructure Security Agency (CISA) and FBI updated an advisory on the group, stating that as of April 2026, Medusa actors have hit more than 500 victims.
Exploiting Newly Announced Exploits
The group has been observed to exploit newly announced exploits within 24 hours, and in some cases, use exploits up to a week before public vulnerability disclosure. According to a recent report from Microsoft, Medusa actors have been targeting victims using software that has not been updated to include new patches.
The advisory notes that Medusa actors do not develop their own zero-day or N-day vulnerabilities, but instead obtain advanced access to exploits from unknown sources or quickly leverage newly announced exploits before potential victims can mitigate vulnerabilities through patching.
Medusa's Affiliate Model
Medusa was originally a closed ransomware gang but transitioned to an affiliate model in 2023, selling its ransomware to hackers who are granted varying levels of access based on their experience and earnings. For newer or less experienced affiliates, important operations such as ransom negotiation may be centrally controlled by the developers.
Medusa actors typically offer lower ransoms to victims if they pay quickly, but they often do research on companies before attacks, basing ransom amounts on publicly announced revenue. While Medusa does remove victim information from its site after a ransom is paid, there is no way to verify whether it is truly deleted.
Technical Advice for Victims
CISA and the FBI included technical advice for victims to investigate Medusa attacks, noting that the hackers use several credential stealing tools before turning to legitimate remote monitoring software to evade detection. The FBI said Medusa actors used remote access software such as AnyDesk, Atera, ConnectWise, eHorus, N-able, BeyondTrust, SimpleHelp, and Splashtop.
Medusa has not added any new victims to its leak site since April, leading several experts to believe that the attack on the University of Mississippi Medical Center drew significant, unwanted law enforcement attention to the group. The group, which emerged in 2021, has repeatedly shown a willingness to target healthcare facilities as well as international and U.S. municipal governments.
Escalation of Operations
The advisory's focus on Medusa's ability to quickly exploit zero-days drew the most interest from researchers, who warned that several groups are increasingly jumping on new vulnerabilities before defenders have a chance to install patches. According to SafeBreach's Adrian Culley, "We're seeing a clear escalation in the speed and coordination of operations... particularly in how quickly newly disclosed and even zero-day vulnerabilities are being operationalized."
Culley added that the hackers tied to Medusa are "moving from initial access to data exfiltration in hours, not days." This escalation in operations highlights the need for organizations to prioritize patching and vulnerability management to prevent such attacks.
- Medusa ransomware gang has been identified with over 200 victims in the last year.
- The group focuses its efforts on the healthcare sector.
- Medusa actors exploit newly announced exploits within 24 hours.
- The group uses several credential stealing tools and legitimate remote monitoring software to evade detection.
The Medusa ransomware gang's ability to quickly exploit zero-days and its affiliate model make it a significant threat to organizations, particularly in the healthcare sector. It is essential for organizations to stay vigilant and prioritize patching and vulnerability management to prevent such attacks.
"We're seeing a clear escalation in the speed and coordination of operations... particularly in how quickly newly disclosed and even zero-day vulnerabilities are being operationalized." - Adrian Culley, SafeBreach
The attack on the University of Mississippi Medical Center highlights the devastating impact of Medusa ransomware attacks on healthcare facilities and the need for organizations to take proactive measures to prevent such attacks.
Conclusion
The Medusa ransomware gang's activities highlight the importance of prioritizing cybersecurity and vulnerability management. Organizations must stay informed about the latest threats and take proactive measures to prevent attacks. By doing so, they can protect themselves and their customers from the devastating impact of ransomware attacks.
- Stay informed about the latest threats and vulnerabilities.
- Prioritize patching and vulnerability management.
- Use legitimate remote monitoring software to detect and prevent attacks.
By following these steps, organizations can reduce the risk of falling victim to Medusa ransomware attacks and protect themselves and their customers from the devastating impact of such attacks.
Source: The Record