logo

Medusa ransomware gang has hit over 500 organizations, CISA warns

ID: 46346e74-806c-5161-ade7-0dda3f6a6bb5

STIX ID: report--46346e74-806c-5161-ade7-0dda3f6a6bb5

Feed Name: Help Net Security

Threat Score
85/100

Date Published: 2026-08-19

Date Updated: 2026-08-19

Author: Sinisa Markovic

...
...

US agencies warn that Medusa ransomware — operating as a Ransomware-as-a-Service with affiliates — has impacted over 500 organizations across healthcare, defense, manufacturing, government, IT, and financial sectors; actors rapidly exploit public vulnerabilities (within 24 hours), use common tools (PowerShell, Mimikatz, AnyDesk, SimpleHelp) and an encryptor (gaze.exe) that appends .medusa, and conduct double-extortion by publishing stolen data and pressuring victims to pay.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.