Medusa Ransomware: RaaS Escalating Double-Extortion Attacks on Critical Infra

Red | Attack
Medusa Ransomware: RaaS Escalating Double-Extortion Attacks on Critical Infrastructure

Summary

Medusa is a ransomware-as-a-service operation first identified in June 2021, distinct from the MedusaLocker and Medusa mobile malware families, that runs double-extortion attacks, encrypting and stealing data before threatening to leak it. Medusa ransomware was linked to over 500 critical-infrastructure victims across healthcare, education, legal, and manufacturing by August 2026.

Medusa's operators pair centrally controlled negotiation with an affiliate model, and the affiliate Storm-1175 stands out for weaponizing 16-plus internet-facing vulnerabilities since 2023, moving from initial access to ransomware deployment in as little as 24 hours. The core Medusa leak site has been quiet since mid-February 2026, and Storm-1175 has since shifted toward a new strain, StormEncryptor. Overall, Medusa exemplifies the convergence of criminal RaaS with fast, state-adjacent exploit capability.

Exploited CVEs Associated with Medusa / Storm-1175
CVENameAffected ProductCISA KEV
CVE-2024-1709ConnectWise ScreenConnect Authentication Bypass VulnerabilityConnectWise ScreenConnectYes
CVE-2023-48788Fortinet FortiClient EMS SQL Injection VulnerabilityFortinet FortiClient EMSYes
CVE-2025-10035Fortra GoAnywhere MFT Deserialization of Untrusted Data VulnerabilityFortra GoAnywhere MFTYes
CVE-2026-1731BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection VulnerabilityBeyondTrust Remote Support / PRAYes

Attack Details

01

Medusa emerged in June 2021 as a ransomware-as-a-service (RaaS) operation, distinct from the similarly named MedusaLocker and the Medusa mobile malware. It began as a closed variant, with a single group controlling development and operations, before adopting an affiliate model, though core functions such as ransom negotiation stayed centrally controlled by the developers.

02

The Medusa ransomware operation runs on double extortion: data is encrypted and simultaneously stolen, with threats to publish it on a dark-web leak site. Victims are typically given 48 hours to respond and can pay to add time to the countdown. Investigators also documented a triple-extortion twist, in which a victim who had already paid was approached again by a separate actor demanding further payment for a working decryptor. By early 2025, Medusa had grown into a serious critical-infrastructure threat, and as of August 2026 it was linked to more than 500 victims across healthcare, education, legal, insurance, technology, and manufacturing.

03

Its most notable recent chapter involves an affiliate tracked as Storm-1175. Assessed as financially motivated and China-linked, it stands apart by weaponizing internet-facing vulnerabilities at extreme speed. Since 2023 it has exploited more than 16 flaws across managed file transfer, mail, remote-access, and gateway products, including at least one as zero-day (CVE-2025-10035). In the fastest cases Storm-1175 moves from initial access to ransomware deployment within 24 hours, though most intrusions run five to six days.

04

Technically, Medusa operators blend living-off-the-land techniques with legitimate remote-monitoring software and tunneling utilities to move quietly, harvest credentials, and exfiltrate data to attacker-controlled cloud storage before deployment. The payload appends a .medusa extension, and the encryptor is designed to disable security tools and delete backups to frustrate recovery.

05

Medusa now exemplifies the convergence of criminal RaaS with state-adjacent exploit capability, its affiliate roster spanning both criminal and state-aligned actors. The core leak site has been quiet since mid-February 2026. Most recently the same affiliate was seen shifting away from Medusa toward a new strain, StormEncryptor, distinguished by a .encrypted extension and a different ransom-note name, after likely exploiting a remote-management authentication-bypass flaw (CVE-2026-18577). The pattern is a reminder that the Medusa platform and its operators keep evolving.


Recommendations

STEP 01
Patch Medusa's Exploited Web-Facing Products

Treat as an emergency any exposure in the products tied to Medusa initial access: Fortra GoAnywhere MFT (CVE-2025-10035), Fortinet FortiClient EMS (CVE-2023-48788), ConnectWise ScreenConnect (CVE-2024-1709), and BeyondTrust Remote Support/PRA (CVE-2026-1731), all listed in the CISA Known Exploited Vulnerabilities catalog.

STEP 02
Isolate and Shield Internet-Facing Systems

Place managed file transfer, email, and remote-access appliances behind a VPN, web application firewall, reverse proxy, or DMZ; where a system cannot be patched immediately, restrict access or take it offline until remediated.

STEP 03
Block and Hunt for the Known Indicators

Ingest the Medusa/Storm-1175 hashes, IP addresses, ransom-note filenames, and negotiation email addresses in this advisory into EDR, SIEM, and firewall tooling, treating the shared Rclone hash 9632d7e4a87ec12fdd05ed3532f7564526016b78972b2cd49a610354d672523c as lower-fidelity given documented reuse across multiple threat actors since 2024.

STEP 04
Enforce MFA and Least Privilege

Require multifactor authentication on webmail, VPNs, RMM consoles, and all privileged accounts, and constrain local-administrator rights to blunt LSASS dumping and registry-based credential caching.

STEP 05
Enable Tamper Protection and Antivirus Hardening

Turn on tenant-wide tamper protection and DisableLocalAdminMerge to prevent attackers from disabling Microsoft Defender or adding exclusions, and enable attack-surface-reduction rules covering LSASS credential theft, obfuscated scripts, web shell creation, and process creation from PsExec/WMI.

STEP 06
Maintain Offline, Immutable Backups

Follow the 3-2-1 backup rule with at least one offline or immutable copy stored off-site under separate credentials, and routinely test restoration to ensure recovery without paying a ransom.


Indicators of Compromise (IoCs)

TypeValue
SHA2560cefeb6210b7103fd32b996beff518c9b6e1691a97bb1cda7f5fb57905c4be96
9632d7e4a87ec12fdd05ed3532f7564526016b78972b2cd49a610354d672523c
e57ba1a4e323094ca9d747bfb3304bd12f3ea3be5e2ee785a3e656c3ab1e8086
5ba7de7d5115789b952d9b1c6cff440c9128f438de933ff9044a68fff8496d19
56b08aa03bd8c0ea094cfeb03d5954ffd857bac42df929dc835eea62f32b09e0
a5a3c3c4fbf5c7db808176db3242c2106995c85f8ba987472ea0e92e59503b55
d3abd4bae082d4c9918447fe82c521567cc7f9b0e5f2d55999a6e5c40fa7fd54
7ffce7f6d7262f214d78e6b7fd8d07119835cba4b04ce334260665d7c8fb369a
b29defbbc4ebaa243c1712ccc4943374f1b6fb864c39ed9f70fceb17eee098db
04b13b6cd5e5291b1cde78975a140feea7fd3bc3777c53caa1ab33426c83bfcc
SHA1ac0dce3b0f5b8d187a2e3f29efc358538fd4aa45
ad5d8dca6ad20b3b9d3b3bd5b2bbb795205f1109
75482072f71b5457351fe3fddcd1379608767c00
1c6913248131b5784b923eff1e76a443f738affc
2df705c9be0465f1c73a9f5d35147723deb16b5e
MD544370f5c977e415981febf7dbb87a85c
80d852cd199ac923205b61658a9ec5bc
d796259c44be852327623fd2e40c47f2
4d0b6e3c9c33550a005e41663a1977cb
eb05429d25fc57b476428cdb0a134b2f
2c7f328feeb94608aaaf99ec70cb0323
8f11d9067da087cb4185fa804caac2df
IPv4185[.]135[.]86[.]149
134[.]195[.]91[.]224
85[.]155[.]186[.]121
143[.]244[.]47[.]89
167[.]88[.]166[.]173
143[.]110[.]243[.]154
37[.]221[.]66[.]239
83[.]138[.]53[.]139
94[.]156[.]67[.]145
45[.]61[.]150[.]94
185[.]135[.]86[.]185
185[.]238[.]231[.]4
185[.]238[.]231[.]16
185[.]238[.]231[.]77
185[.]238[.]231[.]85
185[.]238[.]231[.]98
23[.]234[.]89[.]195
23[.]234[.]93[.]112
23[.]234[.]106[.]242
146[.]70[.]172[.]247
37[.]19[.]21[.]180
155[.]2[.]215[.]69
155[.]2[.]215[.]71
Emailskey[.]medusa[.]serviceteam[@]protonmail[.]com
medusa[.]support[@]onionmail[.]org
mds[.]svt[.]breach[@]protonmail[.]com
mds[.]svt[.]mir2[@]protonmail[.]com
MedusaSupport[@]cock[.]li
URLshxxp[:]//45[.]61[.]150[.]94[:]8000/storm[.]exe
hxxps[:]//3324[.]requestcatcher[.]com/hihi
Domainerp[.]ranasons[.]com
Filenames!!!READ_ME_MEDUSA!!!.txt
openrdp.bat
pu.exe
gaze.exe
lsp.exe
main.exe
moon.exe
RunFileCopy.cmd
def.exe
nezha-agent.exe
mimilib.dll
j.exe
Main_new.exe
command.cmd
Ngconf.txt
Recent Confirmed Breaches

Potential MITRE ATT&CK TTPs

T1190
Initial AccessExploit Public-Facing Application
T1566
Initial AccessPhishing
T1059.001
ExecutionCommand and Scripting Interpreter: PowerShell
T1059.003
ExecutionCommand and Scripting Interpreter: Windows Command Shell
T1569.002
ExecutionSystem Services: Service Execution
T1047
ExecutionWindows Management Instrumentation
T1072
ExecutionSoftware Deployment Tools
T1053.005
ExecutionScheduled Task/Job: Scheduled Task
T1136.001
PersistenceCreate Account: Local Account
T1136.002
PersistenceCreate Account: Domain Account
T1505.003
PersistenceServer Software Component: Web Shell
T1484.001
Privilege EscalationDomain or Tenant Policy Modification: Group Policy Modification
T1562.001
Defense EvasionImpair Defenses: Disable or Modify Tools
T1562.004
Defense EvasionImpair Defenses: Disable or Modify System Firewall
T1070.003
Defense EvasionIndicator Removal: Clear Command History
T1006
Defense EvasionDirect Volume Access
T1027.013
Defense EvasionObfuscated Files or Information: Encrypted/Encoded File
T1112
Defense EvasionModify Registry
T1036
Defense EvasionMasquerading
T1564.012
Defense EvasionHide Artifacts: File/Path Exclusions
T1003.001
Credential AccessOS Credential Dumping: LSASS Memory
T1003.003
Credential AccessOS Credential Dumping: NTDS
T1003.002
Credential AccessOS Credential Dumping: Security Account Manager
T1555
Credential AccessCredentials from Password Stores
T1558
Credential AccessSteal or Forge Kerberos Tickets
T1046
DiscoveryNetwork Service Discovery
T1083
DiscoveryFile and Directory Discovery
T1135
DiscoveryNetwork Share Discovery
T1033
DiscoverySystem Owner/User Discovery
T1049
DiscoverySystem Network Connections Discovery
T1082
DiscoverySystem Information Discovery
T1069.002
DiscoveryPermission Groups Discovery: Domain Groups
T1482
DiscoveryDomain Trust Discovery
T1018
DiscoveryRemote System Discovery
T1021.001
Lateral MovementRemote Services: Remote Desktop Protocol
T1021.002
Lateral MovementRemote Services: SMB/Windows Admin Shares
T1570
Lateral MovementLateral Tool Transfer
T1105
Command and ControlIngress Tool Transfer
T1071.001
Command and ControlApplication Layer Protocol: Web Protocols
T1572
Command and ControlProtocol Tunneling
T1219
Command and ControlRemote Access Software
T1560.001
CollectionArchive Collected Data: Archive via Utility
T1567.002
ExfiltrationExfiltration Over Web Service: Exfiltration to Cloud Storage
T1486
ImpactData Encrypted for Impact
T1490
ImpactInhibit System Recovery
T1489
ImpactService Stop
T1529
ImpactSystem Shutdown/Reboot
T1657
ImpactFinancial Theft

What Next?

At Hive Pro, it is our mission to detect the most likely threats to your organization and to help you prevent them from happening.

Reduce real exposure. Not just vulnerability volume.