Particle.news
Download on the App Store

U.S. Agencies Say Medusa Ransomware Has Hit More Than 500 Critical‑Infrastructure Organizations

The advisory warns Medusa’s affiliate model, rapid weaponization of newly disclosed flaws, and use of legitimate admin tools leave unpatched systems highly vulnerable.

Overview

  • A joint advisory from CISA, the FBI and HHS published Tuesday reports that Medusa actors impacted over 500 critical‑infrastructure victims as of April 2026, up from more than 300 in the March 2025 advisory.
  • Investigators say Medusa runs as a ransomware‑as‑a‑service operation that buys network access from initial access brokers for between $100 and $1,000,000 and sells that access to affiliates who carry out intrusions.
  • The group rapidly weaponizes newly disclosed vulnerabilities—often within 24 hours and sometimes up to a week before public disclosure—and has exploited flaws in ScreenConnect, Fortinet EMS, Fortra GoAnywhere and BeyondTrust.
  • Once inside, actors use living‑off‑the‑land techniques and legitimate remote monitoring and management tools such as AnyDesk and SimpleHelp to steal credentials, exfiltrate data with utilities like Rclone and Bandizip, and deploy an encryptor that kills backups.
  • The agencies urge defenders to patch internet‑facing systems, segment networks, require multi‑factor authentication, maintain offline or immutable backups, report incidents to CISA or the FBI, and note that Medusa uses 48‑hour ransom windows and a $10,000 fee to buy extra time.