logo

Joint Advisory Warns of Extensive Medusa Ransomware Operations

ID: 541a71d1-8267-5e80-b2e8-537fb3befb88

STIX ID: report--541a71d1-8267-5e80-b2e8-537fb3befb88

Feed Name: Halcyon Blog

Threat Score
80/100

Date Published: 2025-03-13

Date Updated: 2026-04-28

...
...

A joint CISA–FBI–MS-ISAC advisory warns that the Medusa ransomware operation, now operating as a Ransomware-as-a-Service, has compromised hundreds of organizations across critical infrastructure sectors in the U.S. and worldwide; attackers recruit affiliates and initial-access brokers, exploit vulnerabilities (including CVE-2023-48788), use phishing and RDP brute-force, deploy tools like Mimikatz and PowerShell to move laterally and exfiltrate data, and employ AES-256/RSA encryption plus deletion of backups and shadow copies to maximize operational disruption and pressure victims with double-extortion tactics.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.