Skip to main content
Emerging ThreatsMalware & Ransomware

Medusa Ransomware Expands Reach with New Tactics, Hundreds More Victims

Hospital corridor with people walking, computer workstation, and door in background.

“Medusa actors operate opportunistically by targeting victims with unpatched software rather than focusing on specific organizations or sectors; however, the Healthcare and Public Health (HPH) Sector has been a frequent victim of Medusa operations,” according to the advisory.

U.S. agencies update advisory: CISA, FBI, and HHS expand findings

On Tuesday, the Cybersecurity and Infrastructure Security Agency (CISA), the FBI, and the Department of Health and Human Services (HHS) published an updated advisory that expands on a March 2025 bulletin and draws on ongoing FBI investigations. The update documents fresh activity by the Medusa ransomware-as-a-service group and provides new detail on the group’s access methods, partnerships with access brokers, and the types of software flaws it has exploited.

Access brokers: a $100–$1 million market and multi-variant reuse

The advisory reports that Medusa pays access brokers anywhere from $100 to $1 million for entry into victims’ environments, with the higher sums reserved for brokers who agree to work exclusively with Medusa. It also notes that most brokers do not work for a single ransomware variant: “most of the brokers work simultaneously for ‘multiple variants at the same time,’” the agencies write, identifying a market in which purchased access is reused across different criminal ransomware families.

Exploited software: Fortra GoAnywhere and BeyondTrust among named targets

The updated advisory calls out specific software vulnerabilities Medusa actors have exploited, naming Fortra GoAnywhere and BeyondTrust flaws. It records an aggressive exploitation tempo: Medusa actors “leverage newly announced exploits within 24 hours and have been observed to use exploits up to a week before public vulnerability disclosure.” The advisory is explicit that there is “no indication Medusa actors develop their own zero-day or N-day vulnerabilities,” and instead says the group prefers to obtain advanced access to exploits from unknown sources or to quickly use newly announced exploits before organizations can implement patches.

Tactics on the ground: living off the land, RMM, and RDP for lateral movement

Once inside a network, the advisory says, Medusa operators often rely on legitimate administrative tools and “living off the land” techniques to evade detection. They may leverage remote monitoring and management (RMM) software and remote access services, including Remote Desktop Protocol (RDP), for lateral movement. The agencies add that Medusa operators commonly use utilities and tools to support credential access, data exfiltration, and eventual ransomware deployment—emphasizing that the group’s playbook favors speed and reuse of common tooling.

Healthcare, industry reporting, and attribution notes

The advisory reiterates that the Healthcare and Public Health (HPH) Sector has been a frequent victim of Medusa operations. Industry reporting referenced in the update underscores the rapid, operational use of Medusa tools: Microsoft described a group it named Storm-1175 making use of Medusa in fast-moving campaigns, and Symantec and Carbon Black reported earlier this year that North Korean hackers were relying on Medusa to target the health care sector. The advisory traces the group’s public identification back to 2021 and reports that the victim tally reported by U.S. agencies rose from more than 300 in March 2025 to more than 500 by April of this year.

What this means for technologists, policymakers, and the Healthcare and Public Health sector

  • Technologists and security teams: The advisory’s account of rapid exploit use—within 24 hours and sometimes before public disclosure—highlights a need to monitor vendor advisories closely and prioritize patching for high-risk products like Fortra GoAnywhere and BeyondTrust when advisories are issued.
  • Policymakers and regulators: The role of access brokers paid up to $1 million and the practice of brokers serving multiple ransomware variants raise questions about the effectiveness of existing controls on illicit access resale and about how quickly public and private reporting can disrupt exploit markets.
  • Healthcare and Public Health organizations: The advisory’s classification of HPH as a frequent target, combined with reporting that Medusa operators favor unpatched software and rapid exploitation, reinforces the specific risk profile called out by CISA, the FBI, and HHS.

The updated advisory paints a picture of a ransomware ecosystem built on rapid exploitation, outsourced access, and the reuse of administrative tools. It also poses a pointed, unanswered question raised in the advisory itself: if Medusa does not develop its own zero-day capabilities, where are the advanced exploits coming from, and how can defenders interrupt that supply of access? The agencies’ update closes one chapter—adding hundreds of victims to the tally and naming exploited products—while leaving the provenance of those exploits and the market dynamics of access brokerage as the next items for investigators and defenders to trace.

Read the original CyberScoop report