(TLP:CLEAR) CISA and Partners Release Cybersecurity Advisory on Medusa Ransomware (Updated August 18, 2026)
Created: Thursday, March 13, 2025 - 14:46
Categories: Cybersecurity, Federal & State Resources, Security Preparedness
August 18, 2026
Summary: This week, CISA and partners released an updated joint advisory on Medusa ransomware, building on the original #StopRansomware advisory (AA25-071A). The update incorporates FBI investigative findings through April 2026 and reflects the ransomware-as-a-service (RaaS) operation’s continued growth, now with more than 500 victims across critical infrastructure sectors, up from roughly 300 at the original publication. The Department of Health and Human Services (HHS) has joined as a co-sealer, adding insight into Medusa’s targeting of the Healthcare and Public Health Sector.
The revised advisory expands the list of exploited CVEs to include Fortra GoAnywhere (CVE-2025-10035) and BeyondTrust (CVE-2026-1731) and notes that Medusa actors often weaponize newly announced vulnerabilities within 24 hours, sometimes exploiting flaws up to a week before public disclosure. It also documents additional tooling for enumeration, credential theft, and stealth, including Nezha, MeshAgent, GSocket, CrackMapExec, and Volume Shadow Copy abuse to steal NTDS.dit and forge Kerberos tickets.
Analyst Note: As with the March advisory, there is still no confirmed Medusa attack against a water or wastewater utility, but the group’s opportunistic model raises the risk to the sector. Medusa does not appear to develop its own zero-days. Instead, actors monitor vulnerability announcements and race to exploit unpatched internet-facing systems before defenders can respond. That pattern rewards utilities that patch known exploited vulnerabilities quickly, particularly on remote access and file transfer products like the ones newly named in this update.
Several of the added TTPs are worth attention because they blend in with normal operations. Medusa actors lean heavily on legitimate remote monitoring and management (RMM) software (AnyDesk, Atera, ConnectWise, SimpleHelp, Splashtop, and others) and often pick whichever tool is already present in the environment. They also place tooling in existing Windows Defender exclusion folders and use living off the land techniques to avoid detection. Utilities can reduce exposure by inventorying which RMM tools are authorized, restricting and monitoring their use, and reviewing Defender exclusions for anything unexpected.
The updated advisory includes a refreshed set of IOCs (with STIX files dated Aug. 18, 2026) and expanded command examples in the appendix.
Original Source: https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-071a
Additional Reading:
- Storm-1175 focuses gaze on vulnerable web-facing assets in high-tempo Medusa ransomware operations
- Under Medusa’s Gaze: How Darktrace Uncovers RMM Abuse in Ransomware Campaigns
March 13, 2025
Summary: Yesterday, CISA—in partnership with the FBI and MS-ISAC—released a joint Cybersecurity Advisory, titled “#StopRansomware: Medusa Ransomware.” This advisory provides tactics, techniques, and procedures (TTPs), indicators of compromise (IOCs), and detection methods associated with known Medusa ransomware activity.
Analyst Note: FBI and CISA urge organizations to act now to mitigate the threat posed by the Medusa ransomware gang. Since February 2025, the group attacked 300 organizations from a variety of critical infrastructure sectors. While no specific attack has been identified in the water and wastewater sector from Medusa ransomware, their propensity to attack critical infrastructure puts the sector at risk.
Immediate actions organizations can take to mitigate Medusa ransomware activity:
- Ensure operating systems, software, and firmware are patched and up to date.
- Segment networks to restrict lateral movement.
- Filter network traffic by preventing unknown or untrusted origins from accessing remote services.
WaterISAC encourages members and network defenders to review the advisory and implement its recommended mitigations to reduce the likelihood and impact of Medusa ransomware incidents.
Original Source: https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-071a
Additional Reading:
- Medusa Ransomware: FBI and CISA Urge Organizations to Act Now to Mitigate Threat
- Medusa Ransomware Hits 40+ Victims in 2025, Demands $100K–$15M Ransom
Related WaterISAC PIRs: 6, 6.1, 7, 7.1, 12
