-
Medusa ransomware has affected more than 500 victims across critical infrastructure sectors, according to a new U.S. government advisory.
-
The group pays initial access brokers from $100 to as much as $1 million for access to target networks.
-
Medusa moves quickly, exploiting newly discovered vulnerabilities as soon as they pop up, including one from BeyondTrust that’s now part of the updated advisory.

The FBI, CISA, and HHS have released an updated version of their joint advisory on Medusa ransomware. The latest report is based on the FBI’s investigations through April 2026. This update drops fresh details, new vulnerabilities, tools, and attack methods, plus signs defenders can watch to catch Medusa in action.
The revised alert also breaks down how Medusa really runs things as a full-blown ransomware business. Its developers now work with affiliates and buy network access from other criminals.
Medusa Has Passed 500 Victims
Medusa first appeared in June 2021. When it first appeared, it ran as a closed operation, which one group controlled. Later on, the operators changed their approach and adopted the ransomware-as-a-service model.
Under this RaaS model, the operators of Medusa don’t launch attacks themselves. They recruit affiliates who carry out the attacks using their ransomware. The developers can also keep control of key tasks, such as ransom talks, when working with less experienced affiliates.
As of April 2026, the FBI says Medusa actors had hit more than 500 victims. Targets include medical organizations, schools, legal firms, insurers, technology companies, and manufacturers.
Healthcare remains a frequent target. That prompted HHS to join the FBI and CISA as a co-author of the updated warning. Medusa uses a double-extortion approach. Attackers steal data before locking systems. They then threaten to publish the stolen information unless the victim pays.
Criminals Can Pay Up to $1 Million for Access
One of the most notable additions concerns initial access brokers. These cybercriminals penetrate into the networks of enterprises and offer access to ransomware gangs.
Medusa usually gets such partners through cybercrime forums and underground markets. The FBI says Medusa actors offer between $100 and $1 million for access. They may also offer brokers exclusive work.
Most brokers, however, appear to work with several ransomware groups at once. This model lets Medusa separate the break-in from the later ransomware attack.
A broker can find and sell access, while an affiliate handles the attack itself. That can help Medusa expand without having to find every target on its own.
Medusa Moves Fast After New Flaws Appear
The updated advisory includes four vulnerabilities for initial access. The first one is CVE-2024-1709 – a flaw in ScreenConnect. The second, CVE-2023-48788, is a vulnerability in Fortinet EMS. Then there’s CVE-2025-10035, a flaw in Fortra GoAnywhere, as well as CVE-2026-1731, a vulnerability present in BeyondTrust products.
The BeyondTrust flaw is especially serious. CVE-2026-1731 stands out as a big one. It’s a critical vulnerability that lets anyone, no login needed, run commands on the target system. NIST scores it a 9.8 on the CVSS 3.1 scale, and BeyondTrust bumps that up to 9.9 under CVSS 4.0. It’s now been added to CISA’s Known Exploited Vulnerabilities list as well.
The FBI says Medusa actors can begin using new exploits within 24 hours of disclosure. In some cases, investigators saw activity up to a week before public disclosure.
The agencies found no evidence that Medusa develops its own zero-day vulnerabilities. Instead, the group appears to obtain advanced exploits or move quickly after flaws become public.
Microsoft previously linked Medusa activity to exploitation of the GoAnywhere flaw. The researchers at this company said the hackers used the flaw for their initial access prior to utilizing remote management software.
Attackers Now Hide Behind Legitimate Tools
Once inside a network, Medusa actors often use software already trusted by the organization. The updated advisory names tools such as Advanced IP Scanner, SoftPerfect Network Scanner, SimpleHelp, MeshAgent, Cloudflared, and Nezha.
The attackers also rely heavily on PowerShell and Windows command tools. They use them to map networks, find systems, gather information, and move between machines.
The FBI also observed Medusa using several methods to hide its activity. These include encoded PowerShell commands, deletion of command history, and credential dumping with Windows components.
Medusa has also abused Active Directory settings to override stricter group policies. That can give attackers more control over systems that would otherwise block their actions.
Hospitals and local governments are paying the price for these tactics. In February and March 2026, the gang disabled the University of Mississippi Medical Center and Passaic County, New Jersey, for nine days, demanding $800,000 from each victim and threatening to leak data by a set deadline.
Data Theft Comes Before Encryption
The updated advisory adds more detail about how Medusa steals and locks data. Attackers use Bandizip to package stolen files and Rclone to move them to their own servers. They may rename Rclone files to make them look less suspicious.
The group also uses built-in remote desktop file transfer features to move smaller batches of sensitive files.
When the attack reaches the final stage, Medusa deploys its encryptor, known as gaze.exe. The malware can stop security, backup, database, and other services. It also deletes shadow copies before encrypting files with AES-256. This makes normal recovery much harder.
Agencies Push for Prompt Patching and Network Segmentation
The guidance is simple: patch exposed systems immediately, particularly if there is a known exploitation of the flaw. Furthermore, they suggest segmenting networks such that the attacker cannot easily jump from one compromised system to another system. The company must be aware of any unusual network traffic and limit remote access to only trustworthy users.
Offline, encrypted, and immutable backups remain another key defense. For organizations that suspect an intrusion, the agencies recommend isolating affected systems and hunting for evidence before removing the attackers. Additionally, it advises changing passwords for administrator and service accounts and removing all remote-access capabilities that are not legitimate.
Paying ransom is not advisable, says the government. The payment does not ensure that the data will be wiped out. Victims of Medusa must report the attack to the FBI or CISA. Healthcare organizations can also seek cyber incident support from HHS.
The full updated advisory, including the technical indicators and detection data, is available from the FBI Internet Crime Complaint Center.