FBI and CISA Issue Joint Advisory on Medusa Ransomware
The FBI and the Cybersecurity and Infrastructure Security Agency (CISA) have issued a joint advisory warning that the Medusa ransomware gang has compromised more than 500 critical infrastructure organizations across the United States since its emergence in June 2021. The advisory urges organizations to apply mitigations immediately and highlights Medusa as one of the most active and destructive ransomware operations currently targeting US critical sectors.
The advisory was coordinated through CISA's #StopRansomware campaign and covers Medusa's tactics, techniques, and procedures (TTPs), indicators of compromise (IOCs), and recommended defensive actions.
Who Is Medusa?
Medusa (not to be confused with MedusaLocker) is a ransomware-as-a-service (RaaS) operation that surfaced in mid-2021. Unlike some other RaaS groups, Medusa operates a Medusa Blog — a data leak site on the dark web where they publicly post stolen data from victims who refuse to pay, creating additional pressure through threatened reputational and regulatory consequences.
The group has targeted organizations across multiple critical infrastructure sectors, including:
- Healthcare and public health
- Education
- Legal and professional services
- Insurance
- Technology
Ransom demands have ranged from $100,000 to $15 million USD, typically paid in Bitcoin.
Attack Methodology
According to the FBI and CISA advisory, Medusa affiliates primarily gain initial access through:
- Phishing campaigns targeting employees to harvest credentials
- Exploiting unpatched internet-facing vulnerabilities in VPNs, RDP, and web applications
- Purchasing access from initial access brokers (IABs) who have already compromised target networks
Once inside, Medusa operators conduct extensive lateral movement using legitimate tools including:
- PowerShell and Windows Management Instrumentation (WMI)
- Living-off-the-land binaries (LOLBins) to evade detection
- Credential harvesting tools to escalate privileges
Before deploying ransomware, affiliates typically exfiltrate sensitive data to support double extortion — threatening to publish stolen files if the ransom is not paid.
Recommended Mitigations
CISA and the FBI recommend the following defensive actions:
- Patch all internet-facing systems — prioritize VPN appliances, firewalls, and RDP endpoints
- Enable multi-factor authentication (MFA) on all remote access solutions and privileged accounts
- Segment networks to limit lateral movement if an attacker gains initial access
- Maintain offline, encrypted backups tested regularly for restoration capability
- Monitor for credential abuse and unusual use of administrative tools
- Review and limit use of RDP — disable if not required, restrict access if needed
- Implement email filtering to reduce phishing exposure
Organizations that detect a Medusa intrusion are urged to contact the FBI and report to CISA at cisa.gov/report rather than pay the ransom.
Scale of the Threat
The 500+ victim count makes this one of the larger disclosed ransomware campaigns targeting US critical infrastructure. The advisory's release reflects growing concern within the US government about the systemic risk ransomware poses to essential services including hospitals, utilities, and government agencies.
Security teams should treat this advisory as a trigger for an immediate review of their ransomware resilience posture — particularly organizations in the sectors Medusa is known to target.