logo

Medusa Ransomware Surges As FBI Share Insight

ID: fb9de3e4-c872-5e4f-ba05-9a04d1398e15

STIX ID: report--fb9de3e4-c872-5e4f-ba05-9a04d1398e15

Feed Name: Cyble Blog

Threat Score
80/100

Date Published: 2025-10-21

Date Updated: 2026-07-16

...
...

**Executive Summary:** The FBI and CISA advisory, corroborated by Cyble data, describes a sharp increase in Medusa RaaS activity in early 2025 (60 victims in the first 72 days; 414 total recorded attacks), with frequent targeting of critical infrastructure sectors; the report documents TTPs including phishing, exploitation of known CVEs (e.g., CVE-2024-1709, CVE-2023-48788), living-off-the-land and legitimate remote management tools, common scanned ports and remote access methods, and provides IoCs (ransom note filename and two file hashes), concluding with prioritized defensive measures such as patching, phishing training, segmentation, and ransomware-resistant backups.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.