Medusa ransomware has affected over 500 critical infrastructure organizations
It continues to spread its reach.

Image by Cybernews.
- Medusa ransomware has affected more than 500 organizations across critical infrastructure sectors worldwide.
- Attackers often buy network access, move through systems, steal files, and encrypt backups and services.
- US agencies urge organizations to patch systems, segment networks, and monitor traffic to reduce ransomware damage.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Medusa ransomware has affected over 500 victims across critical infrastructure sectors since its first detection.
Medusa made its first appearance in June 2021.
Since then, the ransomware operation has evolved from a closed ransomware variant into a ransomware-as-a-service (RaaS) operation, meaning affiliates can use Medusa’s hacking tools and infrastructure developed by skilled hackers in exchange for a slice of all illicit revenue.
According to the latest numbers, Medusa developers and affiliates have affected over 500 organizations and businesses globally.
Organizations in the healthcare sector, defense industry, critical manufacturing business, education, legal, insurance, government services, information technology, and financial services have been on Medusa’s radar.
To distribute its ransomware, Medusa affiliates typically recruit so-called initial access brokers (IABs) in cybercriminal forums and marketplaces.
IABs are criminals engaged in infecting organizations and businesses by exploiting vulnerabilities and weaknesses in their cybersecurity. Once they succeed, they then sell access to corporate networks to Medusa actors, with payments ranging from $100 to $1 million.
Once attackers have gained access to a system, they use a variety of remote access tools already present in the victim’s environment to evade detection, such as AnyDesk, Atera, ConnectWise, eHorus, N-able, BeyondTrust, SimpleHelp, and Splashtop.
Next, the attackers move laterally through the victim’s network to identify files for exfiltration. To do this, they use a program called Rclone to establish communication between the targeted organization and the Medusa Command & Control (C2) servers.
Next, the encryption software, gaze.exe, is deployed across the network to encrypt files and terminate all services related to backups, security, databases, communication, file sharing, and websites. Shadow copies are deleted, and files are encrypted with AES-256 before dropping the ransom note.
Lastly, affiliates manually turn off and encrypt virtual machines and delete their previously installed tools. Victims have the option to add a day to the countdown timer by paying $10,000.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
In a joint advisory, the FBI, Cybersecurity and Infrastructure Security Agency (CISA), and US Department of Health and Human Services (HHS) recommend that organizations in the critical infrastructure implement additional security measures to minimize the impact of Medusa ransomware.
Businesses have to ensure that operating systems, software, and firmware are patched and up to date within a short time frame. To restrict lateral movement and access to sensitive information, corporate networks should be segmented.
Lastly, businesses should filter and monitor their network traffic in order to prevent unknown origins from accessing remote services on internal systems.