CyberSecurityNews

CISA Warns Medusa Ransomware Hackers Steal Data, Kill Security Tools, and Encrypt Entire Networks


The Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the U.S. Department of Health and Human Services (HHS) have jointly released an updated security advisory warning that Medusa ransomware threat actors are actively infiltrating enterprise environments, disabling security tools, exfiltrating sensitive files, and encrypting entire networks.

The updated alert (AA25-071A) reflects comprehensive forensic findings through April 2026, confirming that Medusa has compromised more than 500 organizations across critical infrastructure sectors including healthcare, education, legal, insurance, manufacturing, and technology.

CISA Warns Medusa Ransomware Steals Data

First observed in June 2021 as a closed malware operation, Medusa shifted toward an industrialized Ransomware-as-a-Service (RaaS) model around 2023. Under this structure, core developers lease ransomware payloads to recruited affiliates in exchange for a percentage of extortion revenues.

The syndicate operates a multi-stage double-extortion scheme, exfiltrating intellectual property and patient records, then encrypting target systems and publishing the stolen data on a dedicated dark web leak portal.

HHS joined as a co-author of the updated bulletin due to the group’s relentless targeting of hospitals and public health organizations, which continue to suffer disproportionate operational impact from Medusa ransomware campaigns.

Affiliates gain initial access by collaborating with underground Initial Access Brokers (IABs), which offer payouts ranging from $100 to $1 million for valid corporate access credentials.

Threat actors also target known software vulnerabilities, including the ScreenConnect authentication bypass (CVE-2024-1709), Fortinet FortiClient EMS SQL injection (CVE-2023-48788), Fortra GoAnywhere MFT deserialization flaws, and a newly identified BeyondTrust remote code execution vulnerability tracked as CVE-2026-1731.

As detailed in the joint security bulletin released by CISA and Federal Partners, Medusa operators routinely weaponize public vulnerabilities within twenty-four hours of disclosure, and occasionally prior to public patch availability, making accelerated patching windows essential for defending critical endpoints.

Once inside a network perimeter, operators rely heavily on living-off-the-land techniques using native Windows binaries such as PowerShell cmd.exe, and Windows Management Instrumentation (WMI) to map internal infrastructure without triggering anomalous process alerts.

Adversaries deploy vulnerable or stolen kernel drivers to terminate endpoint detection and response (EDR) software, dump cached credentials from LSASS memory, and abuse legitimate remote monitoring and management (RMM) platforms like AnyDesk, Atera, and SimpleHelp.

These stealth techniques mirror broader industry trends in disabling endpoint detection before launching encryption routines.

Threat actors also deploy tools like Mimikatz, CrackMapExec, and Rclone to harvest network secrets and stage bulk file exfiltration, relying on weaponizing administrative utilities to mask malicious commands behind routine system maintenance.

Threat CharacteristicOperational Specification
Operation ModelRansomware-as-a-Service (RaaS) / Double Extortion
Victim Scale500+ Confirmed Critical Infrastructure Organizations
Initial Access VectorsBroker credentials, ScreenConnect (CVE-2024-1709), Fortinet (CVE-2023-48788), BeyondTrust (CVE-2026-1731)
Payload Binarygaze.exe (Terminates database/backup services, AES-256 encryption)
Communication ChannelsDedicated Tor live chat portals and encrypted Tox messaging
Financial DemandsRansoms up to $15 million (average payouts near $260,000)

The Windows encryption payload, compiled as gaze.exe, systematically stops security services, deletes volume shadow copies, and terminates database management systems before encrypting files with the .medusa extension using AES-256 algorithms.

Victims are typically allotted 48 hours to initiate negotiations via Tor-based live chats or Tox messenger channels. The syndicate frequently offers temporary discounts for prompt payments while threatening to auction stolen corporate datasets if deadlines are missed.

Federal agencies urge critical infrastructure operators to prioritize patching vulnerabilities immediately, segment internal subnets to restrict lateral movement, and strictly limit inbound remote management services.

Security teams should enforce phishing-resistant multifactor authentication, maintain immutable, offline backups, and audit endpoint telemetry for unauthorized RMM installations and anomalous execution of administrative tools.

IoC’s

IOCTypeDescription
143.244.47[.]89IP AddressIP used to access PHP Web Shell (Mullvad VPN)
167.88.166[.]173IP AddressLigolo proxy IP
https://3324.requestcatcher[.]com/hihiURLAdditional URL associated with Ligolo commands
143.110.243[.]154 aka erp.ranasons[.]comIP Address & URLExfiltration IP/domain
185.238.231[.]16IP AddressIP used to access BeyondTrust session (ExpressVPN)
23.234.89[.]195IP AddressIP used to access BeyondTrust session (Mullvad VPN)
146.70.172[.]247IP AddressIP used to access BeyondTrust session (Mullvad VPN)
155.2.215[.]71IP AddressIP used to access BeyondTrust session
23.234.106[.]242IP AddressIP used to access BeyondTrust session (Mullvad VPN)
23.234.93[.]112IP AddressIP used to access BeyondTrust session (Mullvad VPN)
37.19.21[.]180IP AddressIP used to access BeyondTrust session (Mullvad VPN)
155.2.215[.]69IP AddressIP used to access BeyondTrust session
185.238.231[.]98IP AddressIP used to access BeyondTrust session (ExpressVPN)
37.221.66[.]239IP AddressBash TCP reverse shell destination
185.135.86[.]185IP AddressIP associated with SimpleHelp session
83.138.53[.]139IP AddressIP associated with Nezha backdoor
185.238.231[.]4IP AddressIP used to access BeyondTrust session (ExpressVPN)
185.238.231[.]77IP AddressIP used to access BeyondTrust session (ExpressVPN)
185.238.231[.]85IP AddressIP used to access BeyondTrust session (ExpressVPN)
85.155.186[.]121IP AddressIP associated with SimpleHelp session
http://45.61.150[.]94:8000/storm[.]exeURLSimpleHelp agent was downloaded to the victim using this URL
94.156.67[.]145IP AddressIP associated with backdoor
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.



Source link