Skip to main content
Emerging ThreatsMalware & Ransomware

Medusa Ransomware Targets Over 500 Infrastructure Orgs, Expands Tactics

Hospital corridor with staff, medical device, and laptop, well-lit with daylight.

Medusa ransomware has impacted over 500 critical infrastructure organizations as of April 2026, according to a new FBI advisory.

Scale and scope: more than 500 critical infrastructure victims

The updated advisory, published on August 18 and jointly produced by the FBI, CISA and the Department of Health and Human Services, says Medusa has expanded since a March 2025 government advisory that reported more than 300 critical infrastructure victims as of February 2025. The FBI-led notice singles out healthcare as an especially frequent target of Medusa actors and confirms the operation is now implicated in over 500 incidents affecting critical infrastructure.

Faster exploitation windows — within 24 hours, sometimes earlier

The agencies report that exploiting unpatched vulnerabilities remains Medusa’s principal initial access vector. More recently, the group has been observed leveraging exploits within 24 hours after they have been announced, often before many organizations can apply patches. In some cases the advisory says Medusa actors used exploits up to a week before public vulnerability disclosure. The RaaS operation is described as opportunistic — targeting unpatched software rather than specific organizations or sectors — and the advisory states there is no indication Medusa develops its own zero-day or N-day vulnerabilities.

Industry voices in the advisory stressed the operational pressure this creates. “Shrinking windows put far more pressure on defenders to identify and remediate exposed systems before Medusa can take advantage. Dangerous levels of speed can turn a newly disclosed flaw into an active intrusion before many security teams have even finished assessing their exposure,” Nick Tausek, lead security automation architect at Swimlane, commented.

Stealth, lateral movement and new tooling

Since February 2025, the advisory notes, Medusa affiliates have enhanced their post-exploitation playbook to better hide presence, bypass defenses and move laterally to access sensitive data. The group deploys increasingly complex PowerShell stealth techniques that obfuscate payloads and attempt to cover tracks by deleting PowerShell command-line history.

New and repurposed tooling is a core feature of the updated operations. The advisory lists publicly available tools like Nezha — an operations and maintenance server monitoring tool used to allow backdoor visibility to compromised hosts — and GSocket, which allows workstations on different private networks to connect and bypass firewalls. Medusa operators also favor legitimate remote monitoring and management (RMM) software already present in a victim’s environment to evade detection.

For credential theft, the group uses Windows Task Manager Mimikatz and targets the LSA authentication mechanism to record plaintext passwords to a log file. “The group is blending legitimate remote management tools into its operations while using new credential theft methods and overriding security policies to maintain access,” Andrew Costis, engineering manager at AttackIQ, said. “Stolen Active Directory files are especially concerning because they can be used to forge Kerberos tickets. At that point, Medusa isn’t just encrypting systems. It can potentially impersonate trusted users and move through an entire domain with far fewer obstacles.”

Exfiltration, double-extortion and victim interaction

The advisory describes a consistent exfiltration and extortion pattern. Medusa actors use Bandizip to create archives of exfiltrated files and Rclone to transfer data to Medusa command-and-control servers, often obfuscating rclone.exe and associated rclone.conf files by renaming them. Secure file transfer protocol (SFTP) is used to move the encryptor to victim machines.

When encryption occurs the ransomware appends a .medusa file extension, terminates services, deletes shadow copies and drops a ransom note. The group uses a double-extortion model, demanding payment to both restore systems and prevent publication of stolen data. The ransom note typically demands that victims make contact within 48 hours, and Medusa actors often follow up by phone or email if a victim does not respond. Ransom demands are posted on Medusa’s leak site with direct hyperlinks to Medusa-affiliated cryptocurrency wallets.

FBI-recommended response steps for incident containment and eviction

  • Conduct threat hunting to scope intrusions, including searching for logs left by threat actor tooling.
  • Remove command-and-control software such as Nezha and any other remote access methods used by the adversary.
  • Remove local administrator accounts and rotate credentials for service accounts and domain administrator accounts.
  • Ensure the initial intrusion CVE is patched.
  • Use CISA’s Eviction Strategies Tool to assemble a systematic eviction plan.

The advisory frames these recommendations as complementary to prevention and mitigation measures outlined in the earlier March 2025 advisory.

What this means for security teams, healthcare providers, and incident responders

  • Security teams: Expect compressed patching timelines and increased need for rapid detection of exploitation indicators; hunting for artifacts from tools such as Nezha, GSocket and renamed rclone binaries will be critical.
  • Healthcare providers: As a frequently targeted sector, healthcare organizations should prioritize credential rotation, removal of unused local admin accounts and expedited patching for known CVEs.
  • Incident responders: The advisory underscores the importance of coordinated eviction plans and using resources such as CISA’s Eviction Strategies Tool to remove persistent remote access and recover domain control.

Medusa’s shift toward faster exploitation, wider use of legitimate tooling, and a sharpened exfiltration-and-extortion sequence makes its campaigns more time-sensitive and harder to disrupt. The agencies’ guidance is explicit: detection and rapid response matter as much as hardening — and the advisory offers concrete steps for teams that are already responding to active intrusions. Whether defenders can narrow patch and detection windows quickly enough to blunt Medusa’s accelerated tempo remains the concrete operational question left by the agencies’ findings.

https://www.infosecurity-magazine.com/news/critical-infrastructure-medusa/