The Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the U.S. Department of Health and Human Services (HHS) have jointly released an updated security advisory warning that Medusa ransomware threat actors are actively infiltrating enterprise environments, disabling security tools, exfiltrating sensitive files, and encrypting entire networks.
The updated alert (AA25-071A) reflects comprehensive forensic findings through April 2026, confirming that Medusa has compromised more than 500 organizations across critical infrastructure sectors including healthcare, education, legal, insurance, manufacturing, and technology.
CISA Warns Medusa Ransomware Steals Data
First observed in June 2021 as a closed malware operation, Medusa shifted toward an industrialized Ransomware-as-a-Service (RaaS) model around 2023. Under this structure, core developers lease ransomware payloads to recruited affiliates in exchange for a percentage of extortion revenues.
The syndicate operates a multi-stage double-extortion scheme, exfiltrating intellectual property and patient records, then encrypting target systems and publishing the stolen data on a dedicated dark web leak portal.
HHS joined as a co-author of the updated bulletin due to the group’s relentless targeting of hospitals and public health organizations, which continue to suffer disproportionate operational impact from Medusa ransomware campaigns.
Affiliates gain initial access by collaborating with underground Initial Access Brokers (IABs), which offer payouts ranging from $100 to $1 million for valid corporate access credentials.
Threat actors also target known software vulnerabilities, including the ScreenConnect authentication bypass (CVE-2024-1709), Fortinet FortiClient EMS SQL injection (CVE-2023-48788), Fortra GoAnywhere MFT deserialization flaws, and a newly identified BeyondTrust remote code execution vulnerability tracked as CVE-2026-1731.
As detailed in the joint security bulletin released by CISA and Federal Partners, Medusa operators routinely weaponize public vulnerabilities within twenty-four hours of disclosure, and occasionally prior to public patch availability, making accelerated patching windows essential for defending critical endpoints.
Once inside a network perimeter, operators rely heavily on living-off-the-land techniques using native Windows binaries such as PowerShell cmd.exe, and Windows Management Instrumentation (WMI) to map internal infrastructure without triggering anomalous process alerts.
Adversaries deploy vulnerable or stolen kernel drivers to terminate endpoint detection and response (EDR) software, dump cached credentials from LSASS memory, and abuse legitimate remote monitoring and management (RMM) platforms like AnyDesk, Atera, and SimpleHelp.
These stealth techniques mirror broader industry trends in disabling endpoint detection before launching encryption routines.
Threat actors also deploy tools like Mimikatz, CrackMapExec, and Rclone to harvest network secrets and stage bulk file exfiltration, relying on weaponizing administrative utilities to mask malicious commands behind routine system maintenance.
| Threat Characteristic | Operational Specification |
| Operation Model | Ransomware-as-a-Service (RaaS) / Double Extortion |
| Victim Scale | 500+ Confirmed Critical Infrastructure Organizations |
| Initial Access Vectors | Broker credentials, ScreenConnect (CVE-2024-1709), Fortinet (CVE-2023-48788), BeyondTrust (CVE-2026-1731) |
| Payload Binary | gaze.exe (Terminates database/backup services, AES-256 encryption) |
| Communication Channels | Dedicated Tor live chat portals and encrypted Tox messaging |
| Financial Demands | Ransoms up to $15 million (average payouts near $260,000) |
The Windows encryption payload, compiled as gaze.exe, systematically stops security services, deletes volume shadow copies, and terminates database management systems before encrypting files with the .medusa extension using AES-256 algorithms.
Victims are typically allotted 48 hours to initiate negotiations via Tor-based live chats or Tox messenger channels. The syndicate frequently offers temporary discounts for prompt payments while threatening to auction stolen corporate datasets if deadlines are missed.
Federal agencies urge critical infrastructure operators to prioritize patching vulnerabilities immediately, segment internal subnets to restrict lateral movement, and strictly limit inbound remote management services.
Security teams should enforce phishing-resistant multifactor authentication, maintain immutable, offline backups, and audit endpoint telemetry for unauthorized RMM installations and anomalous execution of administrative tools.
IoC’s
| IOC | Type | Description |
|---|---|---|
| 143.244.47[.]89 | IP Address | IP used to access PHP Web Shell (Mullvad VPN) |
| 167.88.166[.]173 | IP Address | Ligolo proxy IP |
| https://3324.requestcatcher[.]com/hihi | URL | Additional URL associated with Ligolo commands |
| 143.110.243[.]154 aka erp.ranasons[.]com | IP Address & URL | Exfiltration IP/domain |
| 185.238.231[.]16 | IP Address | IP used to access BeyondTrust session (ExpressVPN) |
| 23.234.89[.]195 | IP Address | IP used to access BeyondTrust session (Mullvad VPN) |
| 146.70.172[.]247 | IP Address | IP used to access BeyondTrust session (Mullvad VPN) |
| 155.2.215[.]71 | IP Address | IP used to access BeyondTrust session |
| 23.234.106[.]242 | IP Address | IP used to access BeyondTrust session (Mullvad VPN) |
| 23.234.93[.]112 | IP Address | IP used to access BeyondTrust session (Mullvad VPN) |
| 37.19.21[.]180 | IP Address | IP used to access BeyondTrust session (Mullvad VPN) |
| 155.2.215[.]69 | IP Address | IP used to access BeyondTrust session |
| 185.238.231[.]98 | IP Address | IP used to access BeyondTrust session (ExpressVPN) |
| 37.221.66[.]239 | IP Address | Bash TCP reverse shell destination |
| 185.135.86[.]185 | IP Address | IP associated with SimpleHelp session |
| 83.138.53[.]139 | IP Address | IP associated with Nezha backdoor |
| 185.238.231[.]4 | IP Address | IP used to access BeyondTrust session (ExpressVPN) |
| 185.238.231[.]77 | IP Address | IP used to access BeyondTrust session (ExpressVPN) |
| 185.238.231[.]85 | IP Address | IP used to access BeyondTrust session (ExpressVPN) |
| 85.155.186[.]121 | IP Address | IP associated with SimpleHelp session |
| http://45.61.150[.]94:8000/storm[.]exe | URL | SimpleHelp agent was downloaded to the victim using this URL |
| 94.156.67[.]145 | IP Address | IP associated with backdoor |
[.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

