CISA Warns Medusa Ransomware Hackers Steal Data, Kill Security Tools, and Encrypt Entire Networks

August 18, 2026

The Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the U.S. Department of Health and Human Services (HHS) have jointly released an updated security advisory warning that Medusa ransomware threat actors are actively infiltrating enterprise environments, disabling security tools, exfiltrating sensitive files, and encrypting entire networks.

The updated alert (AA25-071A) reflects comprehensive forensic findings through April 2026, confirming that Medusa has compromised more than 500 organizations across critical infrastructure sectors including healthcare, education, legal, insurance, manufacturing, and technology.

CISA Warns Medusa Ransomware Steals Data

First observed in June 2021 as a closed malware operation, Medusa shifted toward an industrialized Ransomware-as-a-Service (RaaS) model around 2023. Under this structure, core developers lease ransomware payloads to recruited affiliates in exchange for a percentage of extortion revenues.

The syndicate operates a multi-stage double-extortion scheme, exfiltrating intellectual property and patient records, then encrypting target systems and publishing the stolen data on a dedicated dark web leak portal.

HHS joined as a co-author of the updated bulletin due to the group’s relentless targeting of hospitals and public health organizations, which continue to suffer disproportionate operational impact from Medusa ransomware campaigns.

Affiliates gain initial access by collaborating with underground Initial Access Brokers (IABs), which offer payouts ranging from $100 to $1 million for valid corporate access credentials.

Threat actors also target known software vulnerabilities, including the ScreenConnect authentication bypass (CVE-2024-1709), Fortinet FortiClient EMS SQL injection (CVE-2023-48788), Fortra GoAnywhere MFT deserialization flaws, and a newly identified BeyondTrust remote code execution vulnerability tracked as CVE-2026-1731.

As detailed in the joint security bulletin released by CISA and Federal Partners, Medusa operators routinely weaponize public vulnerabilities within twenty-four hours of disclosure, and occasionally prior to public patch availability, making accelerated patching windows essential for defending critical endpoints.

Once inside a network perimeter, operators rely heavily on living-off-the-land techniques using native Windows binaries such as PowerShell cmd.exe, and Windows Management Instrumentation (WMI) to map internal infrastructure without triggering anomalous process alerts.

Adversaries deploy vulnerable or stolen kernel drivers to terminate endpoint detection and response (EDR) software, dump cached credentials from LSASS memory, and abuse legitimate remote monitoring and management (RMM) platforms like AnyDesk, Atera, and SimpleHelp.

These stealth techniques mirror broader industry trends in disabling endpoint detection before launching encryption routines.

Threat actors also deploy tools like Mimikatz, CrackMapExec, and Rclone to harvest network secrets and stage bulk file exfiltration, relying on weaponizing administrative utilities to mask malicious commands behind routine system maintenance.

Threat Characteristic Operational Specification
Operation Model Ransomware-as-a-Service (RaaS) / Double Extortion
Victim Scale 500+ Confirmed Critical Infrastructure Organizations
Initial Access Vectors Broker credentials, ScreenConnect (CVE-2024-1709), Fortinet (CVE-2023-48788), BeyondTrust (CVE-2026-1731)
Payload Binary gaze.exe (Terminates database/backup services, AES-256 encryption)
Communication Channels Dedicated Tor live chat portals and encrypted Tox messaging
Financial Demands Ransoms up to $15 million (average payouts near $260,000)

The Windows encryption payload, compiled as gaze.exe, systematically stops security services, deletes volume shadow copies, and terminates database management systems before encrypting files with the .medusa extension using AES-256 algorithms.

Victims are typically allotted 48 hours to initiate negotiations via Tor-based live chats or Tox messenger channels. The syndicate frequently offers temporary discounts for prompt payments while threatening to auction stolen corporate datasets if deadlines are missed.

Federal agencies urge critical infrastructure operators to prioritize patching vulnerabilities immediately, segment internal subnets to restrict lateral movement, and strictly limit inbound remote management services.

Security teams should enforce phishing-resistant multifactor authentication, maintain immutable, offline backups, and audit endpoint telemetry for unauthorized RMM installations and anomalous execution of administrative tools.

IoC’s

IOC Type Description
143.244.47[.]89 IP Address IP used to access PHP Web Shell (Mullvad VPN)
167.88.166[.]173 IP Address Ligolo proxy IP
https://3324.requestcatcher[.]com/hihi URL Additional URL associated with Ligolo commands
143.110.243[.]154 aka erp.ranasons[.]com IP Address & URL Exfiltration IP/domain
185.238.231[.]16 IP Address IP used to access BeyondTrust session (ExpressVPN)
23.234.89[.]195 IP Address IP used to access BeyondTrust session (Mullvad VPN)
146.70.172[.]247 IP Address IP used to access BeyondTrust session (Mullvad VPN)
155.2.215[.]71 IP Address IP used to access BeyondTrust session
23.234.106[.]242 IP Address IP used to access BeyondTrust session (Mullvad VPN)
23.234.93[.]112 IP Address IP used to access BeyondTrust session (Mullvad VPN)
37.19.21[.]180 IP Address IP used to access BeyondTrust session (Mullvad VPN)
155.2.215[.]69 IP Address IP used to access BeyondTrust session
185.238.231[.]98 IP Address IP used to access BeyondTrust session (ExpressVPN)
37.221.66[.]239 IP Address Bash TCP reverse shell destination
185.135.86[.]185 IP Address IP associated with SimpleHelp session
83.138.53[.]139 IP Address IP associated with Nezha backdoor
185.238.231[.]4 IP Address IP used to access BeyondTrust session (ExpressVPN)
185.238.231[.]77 IP Address IP used to access BeyondTrust session (ExpressVPN)
185.238.231[.]85 IP Address IP used to access BeyondTrust session (ExpressVPN)
85.155.186[.]121 IP Address IP associated with SimpleHelp session
http://45.61.150[.]94:8000/storm[.]exe URL SimpleHelp agent was downloaded to the victim using this URL
94.156.67[.]145 IP Address IP associated with backdoor
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

Original article can be found here