Summary
- The Medusa ransomware-as-a-service group has surpassed 500 confirmed victims, up from 300 in March 2025, per an updated US government advisory.
- Medusa relies on paid access brokers — compensated between $100 and $1 million — though most brokers work across multiple ransomware operations simultaneously.
- The group exploits known vulnerabilities opportunistically, including flaws in Fortra GoAnywhere and BeyondTrust, and has leveraged exploits up to a week before public disclosure.
- Healthcare and Public Health organisations have been disproportionately targeted, though Medusa does not appear to restrict itself to specific sectors.
- North Korean threat actors and the group tracked by Microsoft as Storm-1175 have both been observed using Medusa ransomware in recent campaigns.
Victim Count Climbs Sharply
A joint advisory from the Cybersecurity and Infrastructure Security Agency, the FBI, and the Department of Health and Human Services, published this week, updates earlier guidance from March 2025 and reflects ongoing FBI investigations. In the intervening period, confirmed Medusa victims grew from more than 300 to more than 500 — a meaningful acceleration for a group that has been active since 2021.
Access Brokers Fuel the Operation
Medusa operates as a ransomware-as-a-service platform and pays access brokers to supply initial footholds into target environments. Broker fees range from $100 to $1 million, with premium rates reserved for those who work exclusively with Medusa. The advisory notes, however, that most brokers in this ecosystem operate across multiple ransomware variants at the same time — a detail that underscores how interconnected the initial-access economy has become.
Opportunistic, Fast, and Exploit-Hungry
Medusa actors do not appear to discriminate by industry or organisation size. Instead, the advisory describes their approach as opportunistic: they scan for unpatched software and move quickly once a vulnerability is announced. According to the advisory, the group has exploited newly announced vulnerabilities within 24 hours and has been observed using exploits up to a week before those vulnerabilities were publicly disclosed. Named examples include flaws in Fortra GoAnywhere and BeyondTrust products.
No Evidence of Original Zero-Day Research
Despite its speed, the advisory states there is no indication Medusa actors develop their own zero-day or N-day vulnerabilities. Instead, they appear to obtain early access to exploit code from unidentified sources or quickly adapt publicly available exploits before defenders can deploy patches. The distinction matters operationally: Medusa’s edge is speed and access, not novel research capability.
Living Off the Land Once Inside
After gaining initial access, Medusa actors favour legitimate tools and living-off-the-land techniques to avoid triggering endpoint defences. The advisory identifies the use of remote monitoring and management software alongside Remote Desktop Protocol for lateral movement. Common utilities support credential harvesting, data exfiltration, and eventual ransomware deployment — a pattern that makes behavioural detection more important than signature-based controls alone.
Healthcare Remains a Recurring Target
While Medusa does not restrict itself to any single sector, the Healthcare and Public Health sector appears with notable frequency across its victim list. That pattern has also drawn attention from other researchers: Symantec and Carbon Black have separately detailed North Korean threat actors using Medusa tooling to target healthcare organisations, and Microsoft has linked a cluster it tracks as Storm-1175 to Medusa-powered intrusions. The convergence of a criminal RaaS platform and state-aligned actors using the same ransomware raises the risk profile for healthcare security teams.
Why it matters
For CISOs, Medusa represents the industrialised end of ransomware: a service model with a commercial access-broker supply chain, sub-24-hour exploit adoption, and a willingness to hit any sector where unpatched systems offer an opening. The healthcare skew in victim data adds regulatory and patient-safety dimensions beyond the financial exposure. The involvement of state-aligned actors using the same platform blurs attribution and complicates incident response assumptions. Organisations running Fortra GoAnywhere, BeyondTrust products, or any internet-facing infrastructure with outstanding critical patches should treat this advisory as an operational signal, not background reading.
What to do now
- Audit patch status for Fortra GoAnywhere and BeyondTrust products immediately, as these are named in the advisory as exploited by Medusa actors.
- Prioritise patching of all internet-facing systems, particularly those with recently announced critical vulnerabilities, given Medusa’s demonstrated ability to exploit within 24 hours of disclosure.
- Review threat intelligence feeds for pre-disclosure vulnerability exploitation indicators, as Medusa has been observed using exploits before public CVE release.
- Implement behavioural detection controls focused on living-off-the-land techniques, RMM tool abuse, and lateral movement via Remote Desktop Protocol.
- Assess exposure through the access-broker ecosystem by reviewing third-party access pathways, VPN credentials, and any accounts that may have been compromised and sold.
- Healthcare sector security teams should treat Medusa as an elevated and specific threat and review the CISA, FBI, and HHS advisory directly for the full indicator and mitigation set.
