logo

Medusa ransomware group using zero-days to launch attacks within 24 hours of breach, Microsoft says

ID: 4f60d7d5-53c6-5063-b674-400789366c43

STIX ID: report--4f60d7d5-53c6-5063-b674-400789366c43

Feed Name: The Record from Recorded Future News

Threat Score
80/100

Date Published: 2026-04-06

Date Updated: 2026-05-01

...
...

Medusa ransomware operators are actively exploiting newly disclosed vulnerabilities—sometimes days before public disclosure—to quickly compromise organizations (notably a major US hospital and a New Jersey county). Microsoft reports the group moves from access to exfiltration and encryption within 24 hours in many cases, leverages legitimate remote-management tools for lateral movement and persistence, and targets web-facing systems during the disclosure-to-patch window, impacting healthcare, education, professional services, and finance across multiple countries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.