Power plant in the evening showing ransomware and critical infrastructure

FBI, CISA, and HHS Warn about Medusa Ransomware Targeting Over 500 Critical Infrastructure Organizations

U.S. federal authorities have issued a joint cybersecurity alert about Medusa ransomware targeting more than 500 critical infrastructure organizations by April 2026.

First detected in June 2021, Medusa is a ransomware-as-a-service (RaaS) operation that employs double-extortion tactics. It exfiltrates data, encrypts devices, and threatens to publish stolen information on the dark web unless victims pay a ransom. It typically targets organizations in the medical, education, legal, insurance, technology, and manufacturing sectors.

The authoring agencies listed Medusa’s tactics, techniques, and procedures (TTPs), indicators of compromise (IOCs), and mitigations to help network defenders in threat hunting and remediation.

The Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), and the U.S. Department of Health and Human Services (HHS) jointly signed off on the security advisory. The authoring agencies originally issued the advisory in March 2025, when Medusa ransomware compromised 300 organizations.

Medusa ransomware targets over 500 critical infrastructure organizations

According to the authoring agencies, Medusa and its affiliates have targeted over 500 critical infrastructure organizations in the Healthcare and Public Health, Defense Industrial Base, Critical Manufacturing, Government Services and Facilities, Information Technology, and Financial Services. The ransomware group also targets critical infrastructure organizations in the medical, education, legal, insurance, technology, and manufacturing industries.

The authoring agencies noted that Medusa uses initial access brokers to gain initial access to the victims’ networks. The group lists victims on its data leak site with countdowns, contacts them within 48 hours, often avoiding exposing them during negotiations. Medusa offers discounts for quick ransom payments or lists the victims’ data for sale to other threat actors if they refuse to pay.

The agencies also found that Medusa shifted from a closed operation in which developers controlled all operations to an affiliate model that grants affiliates different levels of trust and access based on expertise and profitability. It pays affiliates between $100 and $1 million and also provides them an opportunity to work exclusively for the RaaS operation. However, Medusa ransomware developers centrally control operations, such as ransom negotiations, when dealing with less experienced affiliates.

“The other concerning part of this story is the continued focus by ransomware groups on critical infrastructure and healthcare,” said John Strand, Owner, Black Hills Information Security. “If attackers can disrupt a municipality, hospital, or another organization that serves a large community, they can create tremendous pressure that goes far beyond the financial impact on the organization itself. The dinner bell has been rung.”

Updated Medusa ransomware TTPs and IOCs

The authoring agencies listed updated Medusa TTPs and IOCs the group uses to compromise critical infrastructure. They include using Interactsh URLs to confirm successful exploits and employing PowerShell obfuscation techniques and deleting command history to cover its tracks. It also hides payloads in folders that Windows Defender excludes during active scanning.

The attackers also use the tunneling and pivoting tool Ligolo-ng to create tunnels between the compromised critical organizations’ computers and their own. They also leverage the open-source remote management tool Nezha to maintain visibility into compromised computers and MeshAgent to control compromised computers remotely, and installs webshells to maintain persistence.

Other remote access tools include AnyDesk, Atera, BeyondTrust, ConnectWise, eHorus, N-able, SimpleHelp, and Splashtop. Medusa uses Mimikatz to exfiltrate credentials after disabling security tools to avoid detection, and legitimate Windows tools to exfiltrate small batches of compressed files and credentials.

According to the authoring agencies, Medusa ransomware opportunistically targets critical infrastructure organizations with unpatched software vulnerabilities rather than individual organizations. Additionally, the group does not develop its zero-days but moves fast to exploit recently announced vulnerabilities. It sometimes exploits recently announced vulnerabilities two weeks before security patches were available.

“The fact that attackers were exploiting vulnerabilities up to two weeks before patches were available tells me we’re either dealing with some incredibly talented security researchers and exploit developers, or AI is helping accelerate that process. Possibly both,” added Strand.

The agencies recommended patching software vulnerabilities, segmenting and monitoring networks, and blocking suspicious traffic to block Medusa’s hacking attempts.