Medusa Ransomware Attacks on Critical Infrastructure Entities Continue to Increase
Healthcare and other critical infrastructure sectors are being targeted by the Medusa ransomware group, which has now conducted more than 300 attacks on critical infrastructure entities according to a joint cybersecurity advisory from the Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), and the Multi-State Information Sharing and Analysis Center (MS-ISAC). Medusa ransomware attacks have been increasing, with the Symantec Threat Hunter Team tracking a 42% year-over-year increase in attacks in 2024 and reporting that attacks have continued to increase in 2025. Several threat actors use the Medusa name, including MedusaLocker, a malware variant used in attacks on mobile devices; however, MedusaLocker is unrelated to the Medusa RaaS operation.
Medusa is a ransomware-as-a-service (RaaS) group that has been in operation since at least June 2021. Medusa started out as a private ransomware group; however, the operators switched to the RaaS model and have been recruiting affiliates on cybercriminal marketplaces. In contrast to many other RaaS groups, the developers retain control of key operations such as ransom negotiation.
Like many other RaaS groups, Medusa engages in double extortion, breaching networks, stealing data, and then encrypting files. Victims are told they must pay the ransom to obtain the keys to decrypt data and to prevent the publication of stolen data on the group’s data leak site. There has been one known attack where the victim paid the ransom and was issued with a second ransom demand, which appears to have been issued by an affiliate after allegedly not being paid. It is unclear if this “triple extortion” is a tactic or an isolated case. Victims are told they must make contact within 48 hours and are added to the data leak site, along with a countdown timer. Once the timer reaches zero, data is leaked, although Medusa is known to sell the stolen data before the countdown ends.
Medusa recruits initial access brokers (IABs) – specialists in breaching networks – and encourages IABs to work exclusively for Medusa. The most common initial access vectors used in Medusa ransomware attacks are phishing campaigns to obtain credentials or infect victims with malware and the exploitation of unpatched vulnerabilities. Vulnerabilities known to have been exploited by the group include the ScreenConnect authentication bypass vulnerability, CVE-2024-1709, and the Fortinet EMS SQL injection vulnerability, CVE-2023-48788. The group also uses the bring your own vulnerable driver (BYOVD) tactics, where vulnerable or signed drivers are used in the attack chain to kill antivirus processes and disable security software.
Medusa uses living off the land techniques, deploying commonly used administrative tools such as Windows Management Instrumentation (WMI) and PowerShell to evade detection, move laterally within victims’ networks, and deploy their ransomware payload. Remote access solutions such as AnyDesk, Atera, and ConnectWise are also used in their attacks, including for initial access.
The cybersecurity alert includes indicators of compromise and recommended mitigations for improving defenses against the initial access vectors, hampering lateral movement, and limiting living off the land techniques.
