
The Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the U.S. Department of Health and Human Services (HHS) released an update to the joint Cybersecurity Advisory #StopRansomware: Medusa Ransomware.
The advisory is part of an ongoing series detailing ransomware variants and threat actors. It provides technical details on Medusa ransomware activity, along with detection and mitigation guidance to help protect at-risk government and critical infrastructure organizations.
Medusa is a ransomware-as-a-service variant first identified in June 2021. As of April 2026, Medusa actors have impacted more than 500 victims across multiple critical infrastructure sectors, including Defense Industrial Base, Critical Manufacturing, Government Services and Facilities and Information Technology.
The updated advisory details how Medusa actors gain initial access through brokers, phishing, and exploitation of newly disclosed, unpatched internet-facing vulnerabilities. Medusa actors often use legitimate tools and living off the land techniques to evade detection. They may also leverage remote monitoring and management software and remote access services, including Remote Desktop Protocol, for lateral movement.
Once inside a network, they use common utilities and tools to support credential access, data exfiltration, and ransomware deployment. Medusa uses a double-extortion model, encrypting systems and threatening to publish exfiltrated data if victims do not pay.
CISA, FBI, and HHS urge organizations to implement the advisory’s mitigations, including these key actions:
- Mitigate known vulnerabilities by ensuring operating systems, software, and firmware are patched and up to date within a risk-informed timeframe.
- Segment networks to restrict lateral movement from initially infected devices to other devices in the organization.
- Filter network traffic by preventing unknown or untrusted origins from accessing remote services on internal systems.






















