logo

#StopRansomware: Medusa Ransomware

ID: 730e60c1-5eb1-5a0a-94dc-9ffcc9d52c55

STIX ID: report--730e60c1-5eb1-5a0a-94dc-9ffcc9d52c55

Feed Name: CISA Cybersecurity Advisories

Threat Score
80/100

Date Published: 2025-03-11

Date Updated: 2026-04-19

Author: CISA

...
...

This joint advisory from FBI, CISA, and MS-ISAC documents the Medusa ransomware-as-a-service (RaaS) campaign active through February 2025, describing its affiliate model, double-extortion extortion and data leak site, common TTPs (PowerShell, certutil, PsExec, Rclone, RDP, Mimikatz), observed IOCs (file hashes, ransom notes, negotiation email addresses), and recommended mitigations (patching, MFA, network segmentation, backups, monitoring).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.