Browsing: Medusa

Medusa is a Ransomware-as-a-Service (RaaS) operation that targets critical infrastructure through multiple affiliates. Its attack lifecycle commonly includes exploitation of public-facing vulnerabilities, credential theft, abuse of legitimate administrative tools, and data exfiltration before ransomware deployment. The group also uses malicious drivers to disable or impair security controls and evade detection.

The FBI, the Cybersecurity and Infrastructure Security Agency (CISA), and the Department of Health and Human Services (HHS) have confirmed that Medusa ransomware has now hit more than 500 organizations since the group first appeared in June 2021, according to an updated joint advisory the agencies released in August 2026. The figure marks a jump…

Ransomware crews used to break in themselves. Medusa ransomware mostly buys its way in, and it now counts more than 500 critical infrastructure victims in the United States, up from roughly 300 a year ago. The Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), and the Department of Health and Human…

The Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI) and U.S. Department of Health and Human Services have identified healthcare as a frequent Medusa ransomware victim even as they describe the operation as opportunistic rather than sector-focused.

A joint advisory released Aug. 19 by the FBI, Cybersecurity and Infrastructure Security Agency, and the Department of Health and Human Services provides updates on activity by Medusa, a foreign ransomware-as-a-service variant first identified in 2021. Healthcare has been a frequent victim of Medusa operations, which have also impacted organizations in education, legal, insurance, technology…

Microsoft says China-linked, financially motivated threat actor Storm-1175 has begun using a new ransomware strain called StormEncryptor. The group previously relied on Medusa ransomware. StormEncryptor is written in C++ and encrypts files and adds the .encrypted extension, then leaves a !!!README_FIRST!!!.txt ransom note in each scanned directory. The change suggests an evolution in the group’s…