Executive Summary
In August 2026, the Medusa ransomware-as-a-service group expanded its operations, adding over 200 new victims within a year, totaling more than 500 since its identification in 2021. The group exploits unpatched software vulnerabilities, including Fortra GoAnywhere and BeyondTrust flaws, and employs access brokers to gain initial access, paying between $100 to $1 million. Medusa actors utilize legitimate tools and 'living off the land' techniques to evade detection, leveraging remote monitoring and management software and Remote Desktop Protocol for lateral movement. Once inside a network, they use common utilities to support credential access, data exfiltration, and ransomware deployment.
This incident underscores the critical need for organizations to promptly patch software vulnerabilities and implement robust access controls. The healthcare and public health sectors have been frequent targets, highlighting the importance of securing sensitive data against opportunistic ransomware attacks.
Why This Matters Now
The Medusa ransomware group's rapid expansion and exploitation of unpatched vulnerabilities pose an immediate threat to critical infrastructure sectors, emphasizing the urgency for organizations to enhance their cybersecurity measures and patch management processes.
Attack Path Analysis
Medusa ransomware actors gain initial access by exploiting unpatched software vulnerabilities or through access brokers. Once inside, they escalate privileges using legitimate tools and 'living off the land' techniques. They move laterally within the network by leveraging remote monitoring and management software and Remote Desktop Protocol. For command and control, they utilize common utilities to maintain persistence and control over compromised systems. They exfiltrate data using standard tools before deploying ransomware. Finally, they encrypt files using AES-256 encryption, appending the '.medusa' extension, and leave a ransom note named '!READ_ME_MEDUSA!!!.txt'.
Kill Chain Progression
Initial Compromise
Description
Medusa actors exploit unpatched software vulnerabilities or purchase access from brokers to gain initial entry into target networks.
Related CVEs
CVE-2025-10035
CVSS 9.8A deserialization vulnerability in Fortra's GoAnywhere MFT allows unauthenticated remote code execution via the License Servlet component.
Affected Products:
Fortra GoAnywhere MFT – <= 7.8.3
Exploit Status:
exploited in the wildCVE-2026-23760
CVSS 9.8An authentication bypass vulnerability in SmarterTools' SmarterMail server allows remote attackers to gain unauthorized access.
Affected Products:
SmarterTools SmarterMail – < 17.0.0
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
External Remote Services
Phishing
Command and Scripting Interpreter
Create or Modify System Process: Windows Service
Data Encrypted for Impact
File and Directory Discovery
Inhibit System Recovery
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity
Control ID: Pillar 1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Health Care / Life Sciences
Healthcare sector faces critical ransomware exposure through unpatched vulnerabilities, with Medusa specifically targeting HPH organizations using legitimate remote access tools for lateral movement.
Government Administration
Government entities vulnerable to opportunistic Medusa attacks exploiting unpatched software within 24 hours, requiring enhanced egress filtering and zero trust segmentation controls.
Financial Services
Financial institutions at risk from Medusa's rapid exploit adoption and living-off-the-land techniques, demanding strengthened east-west traffic security and encrypted communications protection.
Information Technology/IT
IT sector faces heightened exposure to Medusa ransomware-as-a-service operations targeting remote management tools, requiring enhanced Kubernetes security and multicloud visibility controls.
Sources
- Medusa ransomware tallies hundreds of new victims, says updated advisory on group’s tacticshttps://cyberscoop.com/medusa-ransomware-tactics-cisa-advisory/Verified
- Medusa Ransomware Fast to Exploit Vulnerabilities, Breached Systemshttps://www.securityweek.com/medusa-ransomware-fast-to-exploit-vulnerabilities-breached-systems/Verified
- Microsoft Warns of Critical GoAnywhere MFT Vulnerability Exploited in Medusa Ransomware Attackshttps://www.thaicert.or.th/en/2025/10/08/microsoft-warns-of-critical-goanywhere-mft-vulnerability-exploited-in-medusa-ransomware-attacks/Verified
- Medusa Ransomware's Actively Exploiting CVE-2025-10035https://www.pcrisk.com/internet-threat-news/34047-medusa-ransomwares-actively-exploiting-cve-2025-10035Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it can significantly limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-based policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While initial access may still occur, the attacker's ability to exploit unpatched vulnerabilities would likely be constrained by limiting unauthorized communications.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges would likely be constrained by limiting access to critical systems and resources.
Control: East-West Traffic Security
Mitigation: The attacker's lateral movement would likely be constrained by restricting unauthorized east-west traffic between workloads.
Control: Multicloud Visibility & Control
Mitigation: The attacker's command and control channels would likely be constrained by monitoring and controlling outbound communications.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's data exfiltration efforts would likely be constrained by enforcing strict egress policies.
While file encryption may still occur, the overall impact would likely be constrained by limiting the attacker's ability to spread ransomware across the network.
Impact at a Glance
Affected Business Functions
- Electronic Health Records (EHR)
- Billing Systems
- Patient Scheduling
- Medical Imaging
Estimated downtime: 14 days
Estimated loss: $5,000,000
Personal Health Information (PHI) of approximately 100,000 patients, including names, Social Security numbers, medical histories, and billing information.
Recommended Actions
Key Takeaways & Next Steps
- • Implement regular patch management to address software vulnerabilities promptly.
- • Utilize Zero Trust Segmentation to limit lateral movement within the network.
- • Enforce Egress Security & Policy Enforcement to monitor and control outbound traffic.
- • Deploy Threat Detection & Anomaly Response systems to identify and respond to suspicious activities.
- • Ensure comprehensive Multicloud Visibility & Control to oversee and manage security across all cloud environments.



