Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Latest News - New Federal Alert Warns U.S. Businesses of Medusa Ransomware Surge
Latest News News & Analysis Ransomware

New Federal Alert Warns U.S. Businesses of Medusa Ransomware Surge

Kirsten DoyleBy Kirsten DoyleMarch 13, 2025Updated:March 13, 20254 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
New Federal Alert Warns U.S. Businesses of Medusa Ransomware Surge
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

In a joint advisory, US federal agencies have issued a cybersecurity warning about a sharp increase in attacks by Medusa ransomware, urging business leaders and IT teams to act immediately to protect their organizations. 

The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and the Multi-State Information Sharing and Analysis Center (MS-ISAC) released the advisory as part of the national #StopRansomware initiative, which focuses on helping entities defend against ransomware threats. 

The Impact on Critical Infrastructure and Business Operations 

Medusa ransomware is a Ransomware-as-a-Service (RaaS) operation first detected in 2021. Since then, Medusa has been used to hit over 300 entities, including those in healthcare, education, legal, insurance, technology, and manufacturing.  

These attacks are especially dangerous because they use double extortion — encrypting company data and threatening to leak it publicly unless a ransom is paid. 

Unlike some ransomware, Medusa is centrally operated, meaning ransom negotiations are tightly controlled, and affiliates are recruited to spread the malware in exchange for a cut of ransom payments.  

“Potential payments between $100 USD and $1 million USD are offered to these affiliates with the opportunity to work exclusively for Medusa. Medusa IABs (affiliates) are known to make use of common techniques,” the advisory says.  

For business leaders, an attack can result in crippled operations, legal liability for leaked data, regulatory fines, and reputational damage. For IT and security teams, the attacks highlight critical vulnerabilities in unpatched systems and weak network segmentation. 

How Medusa Operates 

Medusa actors gain access to networks in several ways, including phishing campaigns that steal user credentials and exploit unpatched software vulnerabilities, including known flaws like:  

ScreenConnect (CVE-2024-1709) — an authentication bypass vulnerability.  

Fortinet EMS (CVE-2023-48788) — an SQL injection flaw. 

Once inside a network, Medusa uses tools like Advanced IP Scanner, PowerShell, and cmd.exe to map out systems and identify valuable data to steal or encrypt. Attackers also leverage legitimate remote management tools already present in victim environments to move undetected. 

Common targets include: 

  • Critical databases (SQL, MySQL, Firebird) 
  • Remote access ports (RDP, SSH) 
  • Web proxies and file transfer ports (FTP, SFTP, HTTP, HTTPS) 

Evading Detection 

Medusa actors are skilled at avoiding detection. They hide malicious files and commands using PowerShell obfuscation and base64 encoding, and use Windows legitimate tools like certutil to avoid triggering antivirus software. 

Also, they disable endpoint detection tools, create firewall rules to maintain access and steal administrator credentials with tools like Mimikatz to spread further inside the network. Once inside, they use Rclone for data exfiltration and deploy the gaze.exe encryptor to lock down files, adding a .medusa extension to encrypted files. 

Organizations Should Act Now 

Business leaders and IT teams are urged to take immediate steps to prevent or limit the impact of a Medusa ransomware attack: 

  • Patch all known vulnerabilities, especially for public-facing services like VPNs, RDP, and third-party remote support tools.  
  • Segment networks to prevent malefactors from moving laterally once inside — limit what each part of your network can access. 
  • Block inbound connections from unknown or untrusted IP addresses. 
  • Limit user permissions and implement multifactor authentication (MFA) to reduce credential-based attacks. 
  • Monitor for abnormal PowerShell or CMD activity, especially those using encoded commands. 
  • Disable unused remote management tools that attackers may leverage, such as AnyDesk or ConnectWise, unless explicitly needed. 
  • Regularly back up data offline and test restoration processes to ensure business continuity in case of an attack. 
  • Educate employees on how to spot phishing emails — a common entry point for these attacks. 

The Bigger Picture 

The Medusa ransomware advisory comes amid a broader rise in ransomware attacks targeting critical infrastructure and major business sectors. These incidents are not only IT issues but business risks that can halt operations, disrupt supply chains and expose sensitive client and employee data. 

Executive teams should insist on a ransomware risk assessment from their security leaders. IT teams should verify that critical patches have been applied and review incident response plans to ensure readiness. Entities should coordinate with law enforcement and industry groups to stay informed of the latest threats. 

Kirsten Doyle
Kirsten Doyle
Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

  • Kirsten Doyle
    AI-Powered Attacks Become Top Concern for Security Professionals, New Filigran Survey Reveals
  • Kirsten Doyle
    ShinyHunters targets Oracle PeopleSoft customers through critical zero-day
  • Kirsten Doyle
    SIG report: AI-generated code is linked to twice the security risk and rising technical debt
  • Kirsten Doyle
    Miasma worm spreads from Red Hat packages to Microsoft repositories

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Roundcube RCE Vulnerability Disclosed Early Amid Active Exploitation

June 10, 20255 Mins Read

Fake Indian Government Portal Used to Spread Cross-Platform Malware in Suspected APT36 Campaign

May 13, 20253 Mins Read

Threat Actors Exploit DeepSeek’s Popularity to Distribute Infostealers on PyPI 

February 4, 20254 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}