LIVE · cybersecurity feed
Live wire
8,539 reasons to rethink how vulnerabilities get patched'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllersNSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technologyUS warns of AI-powered attacks on Siemens PLCs in critical infrastructureCVE-2026-19490 · CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler GatewayA California county wants to hire Tina Peters to help run its electionsThe long tail of Clop’s PTC hack is just beginning to emergeOracle Critical Patch Update, August 2026 Security Update ReviewCVE-2026-65400 · Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active ExploitationOver 500 Critical Infrastructure Organizations Hit by Medusa Ransomware
ransomwarecritical

Over 500 Critical Infrastructure Organizations Hit by Medusa Ransomware

The FBI warned that the RaaS operation has significantly enhanced its tactics, techniques and procedures, making it harder for defenders to counter

zeroday.news ·

The Medusa ransomware-as-a-service (RaaS) operation has impacted over 500 critical infrastructure organizations as of April 2026, according to a recent advisory issued by the FBI, CISA, and the Department of Health and Human Services. This marks a significant increase from an earlier US government advisory in March 2025, which reported over 300 critical infrastructure organizations affected by February 2025. The healthcare industry has been particularly targeted by Medusa actors.

The Medusa ransomware variant, first identified in June 2021, initially operated as a closed ransomware group before transitioning to an affiliate model in early 2023. Since February 2025, the group has expanded its techniques and tooling, enhancing its initial access and post-exploitation capabilities.

Medusa continues to primarily gain initial access by exploiting unpatched vulnerabilities. The group has been observed leveraging exploits within 24 hours of public disclosure, and in some instances, up to a week before a vulnerability is publicly announced. The RaaS group is described as opportunistic, targeting organizations with unpatched software rather than specific sectors, and there is no indication that Medusa actors develop their own zero-day or N-day vulnerabilities. A new tactic involves the use of Interactsh dynamic URLs to confirm successful exploitation of compromised hosts.

Post-exploitation, Medusa actors have improved their ability to evade detection, bypass defenses, move laterally within networks, and access sensitive data. They deploy increasingly complex PowerShell stealth techniques to obfuscate payloads and delete PowerShell command line history to cover their tracks.

New tools supporting command and control (C2) and stealth include publicly available utilities like Nezha, an operations and maintenance server monitoring tool that provides backdoor visibility to compromised hosts, and GSocket, which enables workstations on different private networks to connect and bypass firewalls. Medusa also utilizes legitimate remote monitoring and management (RMM) software already present in the victim’s environment to move laterally and identify files for exfiltration, thereby evading detection.

For credential harvesting, Medusa actors use Mimikatz, including directly stealing credentials from the Local Security Authority (LSA) authentication mechanism and recording plaintext passwords to a log file. Stolen Active Directory files are particularly concerning as they can be used to forge Kerberos tickets, allowing the threat actors to impersonate trusted users and move through an entire domain with fewer obstacles.

For data exfiltration, Medusa actors install and use Bandizip to archive files and Rclone to transfer data to their C2 servers. They obfuscate rclone.exe and associated rclone.conf files by renaming them. Secure File Transfer Protocol (SFTP) is used to transfer the encryptor to victim machines. Encrypted files are marked with a .medusa file extension.

The ransomware operation employs a double-extortion model. Before encryption, all services are terminated, and shadow copies are deleted. A ransom note is then dropped, typically demanding contact within 48 hours. If victims do not respond, Medusa actors often contact them directly via phone or email. Ransom demands are posted on Medusa’s leak site, with direct hyperlinks to Medusa-affiliated cryptocurrency wallets.

The advisory recommends that security teams focus on incident response in addition to prevention and mitigation. Key response actions include conducting threat hunting to scope the intrusion, removing C2 software and other remote access methods, removing local administrator accounts, rotating credentials for service accounts and domain administrator accounts, patching the initial intrusion CVE, and utilizing CISA’s Eviction Strategies Tool to develop countermeasures for a systematic eviction plan.

ransomware
ShareXLinkedInWhatsAppFacebook

More News

view all →
ransomware

Rogue ransomware affiliate poses as data recovery firm to steal payments

A suspected ransomware affiliate is posing as a ransomware recovery service called "Ransom Busters," contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee. [...]

ai

OpenAI confirms ChatGPT is down as logins and signups fail

ChatGPT is experiencing a major outage, and users are unable to sign in, create accounts, or load chats, including previous conversations. [...]

ai

Smashing Security podcast #481: Never say this to a robot dog

At Black Hat this month, a group of security researchers took a $9,000 robot dog, plugged Google's AI into its brain, and jailbroke it by telling it - with a completely straight face - that it was a Pokemon. What followed involved a wall, a blue ice chest, and anyone in the room wearing white shoes. Oh, and did we mention you can buy a flamethrower attachment? Meanwhile, in Salzburg, 280 gold stat

aicritical

'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllers

'It is an active threat'

cloud

Sakura Internet hack exposes data of up to 1.36 million accounts

Japanese cloud and data center service provider Sakura Internet disclosed that hackers accessed its sales management system, where customer contract and membership information is stored. [...]

breach

Healthtech firm CareCloud data breach impacts 3.7 million patients

U.S. healthcare IT company CareCloud disclosed that the data breach incident it suffered earlier this year has impacted more than 3.7 million individuals. [...]