Medusa Ransomware Evolves Tactics, Adds Hundreds of Victims
An updated government advisory highlights Medusa ransomware's shift to access brokers and rapid exploitation of vulnerabilities, significantly increasing its victim count.

The ransomware-as-a-service group Medusa has adopted new tactics to enhance its access capabilities and has added hundreds of victims over the past year, according to an updated advisory from the Cybersecurity and Infrastructure Security Agency (CISA), FBI, and the Department of Health and Human Services (HHS).
The advisory details Medusa's increasing reliance on access brokers, offering them compensation ranging from $100 to $1 million, with higher payouts for exclusive partnerships. However, many brokers work with multiple ransomware variants simultaneously, indicating a complex and interconnected cybercrime ecosystem.
This updated advisory builds upon a March 2025 publication, incorporating findings from ongoing FBI investigations. It specifically calls out the exploitation of vulnerabilities in software such as Fortra GoAnywhere and BeyondTrust. Medusa actors are characterized by their opportunistic approach, targeting organizations with unpatched software rather than focusing on specific sectors, though the Healthcare and Public Health (HPH) sector has been a frequent target.
A concerning aspect highlighted is Medusa's speed in exploiting vulnerabilities. The group has been observed leveraging newly announced exploits within 24 hours and has even used exploits up to a week before their public disclosure. This rapid adoption suggests a sophisticated intelligence gathering and exploitation pipeline, though the advisory notes that Medusa actors do not appear to develop their own zero-day or N-day vulnerabilities, preferring to acquire exploits or quickly capitalize on publicly disclosed ones.
The effectiveness of these evolving tactics is evident in the group's victim count. Between March 2025 and April 2026, the number of victims detailed in the advisory surged from over 300 to more than 500. The Medusa ransomware operation was first identified in 2021.
Medusa actors are adept at evading detection by employing legitimate tools and 'living off the land' techniques. They frequently utilize remote monitoring and management (RMM) software and remote access services, such as Remote Desktop Protocol (RDP), to facilitate lateral movement within compromised networks. Once inside, they employ common utilities for credential access, data exfiltration, and the deployment of their ransomware payload.
This evolving threat landscape has been noted by other security researchers. Earlier in 2026, Microsoft detailed how a group it tracked as Storm-1175 was using Medusa ransomware in rapid attack campaigns. Similarly, Symantec and Carbon Black have previously reported on North Korean hackers using Medusa to target the healthcare sector, underscoring the group's persistent focus on this critical industry.
The updated advisory serves as a crucial warning to organizations, particularly within the healthcare sector, to prioritize patching known vulnerabilities and to implement robust security measures to detect and prevent the lateral movement and data exfiltration tactics employed by the Medusa ransomware group.
The updated advisory from CISA and the FBI reveals that the Medusa ransomware group has now impacted over 500 victims as of April 2026, a significant increase from previous estimates. Notably, the group has demonstrated an alarming capability to exploit newly announced vulnerabilities within 24 hours, and has been observed using exploits even before public disclosure, often targeting the healthcare sector.
The latest advisory from CISA, FBI, and HHS provides updated details on Medusa ransomware's evolution into a sophisticated Ransomware-as-a-Service (RaaS) model, highlighting its rapid exploitation of newly disclosed vulnerabilities, including CVE-2024-1709 and CVE-2023-48788. The report also details the group's advanced tactics such as disabling security tools using kernel drivers and leveraging living-off-the-land techniques with native Windows binaries, alongside the use of tools like Mimikatz for credential harvesting and data exfiltration.