Cyber Security News

CISA Warns Medusa Ransomware Hackers Steal Data, Kill Security Tools, and Encrypt Entire Networks

The Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the U.S. Department of Health and Human Services (HHS) have jointly released an updated security advisory warning that Medusa ransomware threat actors are actively infiltrating enterprise environments, disabling security tools, exfiltrating sensitive files, and encrypting entire networks.

The updated alert (AA25-071A) reflects comprehensive forensic findings through April 2026, confirming that Medusa has compromised more than 500 organizations across critical infrastructure sectors including healthcare, education, legal, insurance, manufacturing, and technology.

CISA Warns Medusa Ransomware Steals Data

First observed in June 2021 as a closed malware operation, Medusa shifted toward an industrialized Ransomware-as-a-Service (RaaS) model around 2023. Under this structure, core developers lease ransomware payloads to recruited affiliates in exchange for a percentage of extortion revenues.

The syndicate operates a multi-stage double-extortion scheme, exfiltrating intellectual property and patient records, then encrypting target systems and publishing the stolen data on a dedicated dark web leak portal.

HHS joined as a co-author of the updated bulletin due to the group’s relentless targeting of hospitals and public health organizations, which continue to suffer disproportionate operational impact from Medusa ransomware campaigns.

Affiliates gain initial access by collaborating with underground Initial Access Brokers (IABs), which offer payouts ranging from $100 to $1 million for valid corporate access credentials.

Threat actors also target known software vulnerabilities, including the ScreenConnect authentication bypass (CVE-2024-1709), Fortinet FortiClient EMS SQL injection (CVE-2023-48788), Fortra GoAnywhere MFT deserialization flaws, and a newly identified BeyondTrust remote code execution vulnerability tracked as CVE-2026-1731.

As detailed in the joint security bulletin released by CISA and Federal Partners, Medusa operators routinely weaponize public vulnerabilities within twenty-four hours of disclosure, and occasionally prior to public patch availability, making accelerated patching windows essential for defending critical endpoints.

Once inside a network perimeter, operators rely heavily on living-off-the-land techniques using native Windows binaries such as PowerShell cmd.exe, and Windows Management Instrumentation (WMI) to map internal infrastructure without triggering anomalous process alerts.

Adversaries deploy vulnerable or stolen kernel drivers to terminate endpoint detection and response (EDR) software, dump cached credentials from LSASS memory, and abuse legitimate remote monitoring and management (RMM) platforms like AnyDesk, Atera, and SimpleHelp.

These stealth techniques mirror broader industry trends in disabling endpoint detection before launching encryption routines.

Threat actors also deploy tools like Mimikatz, CrackMapExec, and Rclone to harvest network secrets and stage bulk file exfiltration, relying on weaponizing administrative utilities to mask malicious commands behind routine system maintenance.

Threat CharacteristicOperational Specification
Operation ModelRansomware-as-a-Service (RaaS) / Double Extortion
Victim Scale500+ Confirmed Critical Infrastructure Organizations
Initial Access VectorsBroker credentials, ScreenConnect (CVE-2024-1709), Fortinet (CVE-2023-48788), BeyondTrust (CVE-2026-1731)
Payload Binarygaze.exe (Terminates database/backup services, AES-256 encryption)
Communication ChannelsDedicated Tor live chat portals and encrypted Tox messaging
Financial DemandsRansoms up to $15 million (average payouts near $260,000)

The Windows encryption payload, compiled as gaze.exe, systematically stops security services, deletes volume shadow copies, and terminates database management systems before encrypting files with the .medusa extension using AES-256 algorithms.

Victims are typically allotted 48 hours to initiate negotiations via Tor-based live chats or Tox messenger channels. The syndicate frequently offers temporary discounts for prompt payments while threatening to auction stolen corporate datasets if deadlines are missed.

Federal agencies urge critical infrastructure operators to prioritize patching vulnerabilities immediately, segment internal subnets to restrict lateral movement, and strictly limit inbound remote management services.

Security teams should enforce phishing-resistant multifactor authentication, maintain immutable, offline backups, and audit endpoint telemetry for unauthorized RMM installations and anomalous execution of administrative tools.

IoC’s

IOCTypeDescription
143.244.47[.]89IP AddressIP used to access PHP Web Shell (Mullvad VPN)
167.88.166[.]173IP AddressLigolo proxy IP
https://3324.requestcatcher[.]com/hihiURLAdditional URL associated with Ligolo commands
143.110.243[.]154 aka erp.ranasons[.]comIP Address & URLExfiltration IP/domain
185.238.231[.]16IP AddressIP used to access BeyondTrust session (ExpressVPN)
23.234.89[.]195IP AddressIP used to access BeyondTrust session (Mullvad VPN)
146.70.172[.]247IP AddressIP used to access BeyondTrust session (Mullvad VPN)
155.2.215[.]71IP AddressIP used to access BeyondTrust session
23.234.106[.]242IP AddressIP used to access BeyondTrust session (Mullvad VPN)
23.234.93[.]112IP AddressIP used to access BeyondTrust session (Mullvad VPN)
37.19.21[.]180IP AddressIP used to access BeyondTrust session (Mullvad VPN)
155.2.215[.]69IP AddressIP used to access BeyondTrust session
185.238.231[.]98IP AddressIP used to access BeyondTrust session (ExpressVPN)
37.221.66[.]239IP AddressBash TCP reverse shell destination
185.135.86[.]185IP AddressIP associated with SimpleHelp session
83.138.53[.]139IP AddressIP associated with Nezha backdoor
185.238.231[.]4IP AddressIP used to access BeyondTrust session (ExpressVPN)
185.238.231[.]77IP AddressIP used to access BeyondTrust session (ExpressVPN)
185.238.231[.]85IP AddressIP used to access BeyondTrust session (ExpressVPN)
85.155.186[.]121IP AddressIP associated with SimpleHelp session
http://45.61.150[.]94:8000/storm[.]exeURLSimpleHelp agent was downloaded to the victim using this URL
94.156.67[.]145IP AddressIP associated with backdoor
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

2 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

12 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

13 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

13 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

13 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

14 hours ago