HomeSecurityMedusa ransomware: Has targeted over 300 organizations in critical infrastructure

Medusa ransomware: Has targeted over 300 organizations in critical infrastructure

CISA , FBI, and MS-ISAC say the Medusa ransomware had affected over 300 organizations related to the United States' critical infrastructure.

Medusa ransomware critical infrastructure

“By February 2025, Medusa developers and affiliates had affected over 300 victims from various critical infrastructure sectors, including medical, education, legal, insurance, technology, and industry,” the security services.

“The FBI, CISA, and MS-ISAC encourage organizations to implement the recommendations in the Mitigations of this advisory to reduce the likelihood and impact of Medusa ransomware incidents.“.

See also: Microsoft: North Korean hackers join Qilin ransomware gang

The services recommend that network defenders take the following measures:

  • Mitigate known security vulnerabilities and ensure that operating systems, software, and firmware are patched within a reasonable timeframe,
  • Segment networks to limit lateral movement between infected devices and other devices within the organization and
  • Filter network traffic by blocking access from unknown or untrusted sources.

The Medusa ransomware emerged in January 2021, but became more prolific in 2023, when it launched the data-leakage, Medusa Blog, to pressure victims into paying ransom.

The gang has claimed responsibility for over 400 victims worldwide and gained media attention in 2023 for an attack on Minneapolis Public Schools. The group also leaked files allegedly stolen from Toyota Financial Services, a subsidiary of Toyota Motor Corporation, in November 2023.

See also: Multiple schools report breaches after ransomware attack on CCC

In the first two months of 2025, the group has claimed responsibility for more than 40 attacks, according to new data from Symantec. The hackers behind Medusa ransomware typically demand ransoms ranging from $100,000 to $15 million.

Hackers often launch their attacks by exploiting known security vulnerabilities in popular applications. The Medusa ransomware gang also uses initial access brokers to compromise networks.

Medusa ransomware: Has targeted over 300 organizations in critical infrastructure

“The developers of Medusa ransomware typically recruit initial access brokers (IABs) on cybercriminal forums and marketplaces to gain initial access to potential victims,” the agencies said. “Potential payments of between $100 USD and $1 million USD are offered to these affiliates to work exclusively for Medusa.”

After gaining access, hackers use remote management and monitoring (RMM) software such as SimpleHelp, AnyDesk, or MeshAgent, for permanent access.

They also use the Bring Your Own Vulnerable Driver (BYOVD) technique to terminate antivirus processes (via KillAV).

See also: Akira Ransomware gang used webcam for attacks

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

“The use of legitimate RMM software, PDQ Deploy, is another hallmark of Medusa ransomware attacks,” Symantec said. “It is commonly used by attackers to install other tools and files and move into the victims’ network.”

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS