ctipilot.ch

Medusa

malware · malware:medusa single-source

Ransomware-as-a-service operation that emerged in 2021 as a closed group and moved to an affiliate model in 2023, tracked by CISA, the FBI and HHS in the joint #StopRansomware advisory AA25-071A. The 2026-08-18 update, carrying FBI investigative data through April 2026, raised the recorded victim count from more than 300 to more than 500; the only sector list the cited reporting carries covers medical, education, legal, insurance and manufacturing. The agencies state affiliates exploit newly announced vulnerabilities within 24 hours and have been observed using exploits up to a week before public disclosure while developing no zero-day or N-day flaws of their own, obtaining that exploit access from sources the agencies could not identify. Separately from exploit access, initial-access brokers who sell entry into victim networks are paid between $100 and $1 million with a premium for exclusivity; post-compromise the affiliates use legitimate remote-management software and RDP rather than bespoke tooling. The group had added no new leak-site victims since April at the time of the update (CyberScoop and The Record, both 2026-08-18). Distinct from the unrelated MedusaLocker and MedusaHVNC families already tracked in this registry.

Coverage timeline
6
first 2026-06-21 → last 2026-08-19
Peak priority
high
1 high · 5 notable
Sources cited
10
9 hosts
Sections touched
4
active-threats, updates, weekly-annual-reports
Co-occurring entities
3
see Related entities below
ATT&CK techniques
6
pinned v19.2 · see below

ATT&CK techniques

6 techniques observed across 2 entries — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-19/medusa-raas-advisory-update-24-hour-weaponisation · ATT&CK page ↗

T1190Exploit Public-Facing Application×2

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-08-19/medusa-raas-advisory-update-24-hour-weaponisation · 2026-08-12/n-able-n-central-storm-1175-stormencryptor · ATT&CK page ↗

Execution TA0002

T1072Software Deployment Tools×1

Adversaries may gain access to and use centralized software suites installed within an enterprise to execute commands and move laterally through the network. Configuration management and software deployment applications may be used in an enterprise network or cloud environment for routine administration purposes. These systems may also be integrated into CI/CD pipelines. Examples of such solutions include: SCCM, HBSS, Altiris, AWS Systems Manager, Microsoft Intune, Azure Arc, and GCP Deployment Manager.

Evidence: 2026-08-12/n-able-n-central-storm-1175-stormencryptor · ATT&CK page ↗

Persistence TA0003

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-19/medusa-raas-advisory-update-24-hour-weaponisation · ATT&CK page ↗

Privilege Escalation TA0004

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-19/medusa-raas-advisory-update-24-hour-weaponisation · ATT&CK page ↗

Stealth TA0005

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-19/medusa-raas-advisory-update-24-hour-weaponisation · ATT&CK page ↗

Lateral Movement TA0008

T1021.001Remote Services: Remote Desktop Protocol×1

Adversaries may use Valid Accounts to log into a computer using the Remote Desktop Protocol (RDP). The adversary may then perform actions as the logged-on user.

Evidence: 2026-08-19/medusa-raas-advisory-update-24-hour-weaponisation · ATT&CK page ↗

T1072Software Deployment Tools×1

Adversaries may gain access to and use centralized software suites installed within an enterprise to execute commands and move laterally through the network. Configuration management and software deployment applications may be used in an enterprise network or cloud environment for routine administration purposes. These systems may also be integrated into CI/CD pipelines. Examples of such solutions include: SCCM, HBSS, Altiris, AWS Systems Manager, Microsoft Intune, Azure Arc, and GCP Deployment Manager.

Evidence: 2026-08-12/n-able-n-central-storm-1175-stormencryptor · ATT&CK page ↗

Command and Control TA0011

T1219Remote Access Tools×2

An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network. Remote access tools create a session between two trusted hosts through a graphical interface, a command line interaction, a protocol tunnel via development or management software, or hardware-level access such as KVM (Keyboard, Video, Mouse) over IP solutions. Desktop support software (usually graphical interface) and remote management software (typically command line interface) allow a user to control a computer remotely as if they are a local user inheriting the user or software permissions. This software is commonly used for troubleshooting, software installation, and system management. Adversaries may similarly abuse response features included in EDR and other defensive tools that enable remote access.

Evidence: 2026-08-19/medusa-raas-advisory-update-24-hour-weaponisation · 2026-08-12/n-able-n-central-storm-1175-stormencryptor · ATT&CK page ↗

Impact TA0040

T1486Data Encrypted for Impact×2

Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.

Evidence: 2026-08-19/medusa-raas-advisory-update-24-hour-weaponisation · 2026-08-12/n-able-n-central-storm-1175-stormencryptor · ATT&CK page ↗

Story timeline

  1. 2026-08-19Medusa's joint advisory update puts a number on the patch race: affiliates weaponise newly announced flaws within 24 hours, and the agencies find no sign the group develops any of them itself
    active-threatsA ransomware crew that develops no zero-days still beats the patch window, on exploits it obtains from sources the agencies cannot identify
  2. 2026-08-12UPDATE — the N-central exploitation has an actor and a payload: Microsoft assesses Storm-1175 is behind it, deploying a new ransomware strain called StormEncryptor from the day the flaw was disclosed
    updatesThe RMM auth-bypass chain tracked here since 3 August is now attributed to a China-linked ransomware actor with a new encryptor
  3. 2026-06-29Healthcare
    weekly-sector-patterns
  4. 2026-06-29ESET "Killing me gently" — a de-facto mid-year RaaS-tooling report
    weekly-annual-reports
  5. 2026-06-22Healthcare — third-party exposure and a 16-month notification gap
    weekly-sector-patterns
  6. 2026-06-21HCRG Care Group first notifies patients of a February 2025 Medusa breach — 16 months on
    active-threats

Where this entity is cited

  • active-threats2
  • weekly-sector-patterns2
  • weekly-annual-reports1
  • updates1

Source distribution

  • therecord.media2 (20%)
  • cyberscoop.com1 (10%)
  • eset.com1 (10%)
  • healthsystemcio.com1 (10%)
  • hipaajournal.com1 (10%)
  • hipaapulse.com1 (10%)
  • microsoft.com1 (10%)
  • sec.gov1 (10%)
  • other1 (10%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

All cited sources (10)

Entries about Medusa (6)

2026-08-19 · view entry permalink →

NOTABLENATOB1

Medusa's joint advisory update puts a number on the patch race: affiliates weaponise newly announced flaws within 24 hours, and the agencies find no sign the group develops any of them itself

CISA, the FBI and the Department of Health and Human Services published an update to the joint #StopRansomware advisory on Medusa on 2026-08-18, folding in FBI investigative findings through April 2026. The headline number is cumulative rather than current: CyberScoop records that "the victim tally in the advisory jumped from more than 300 to more than 500" (CyberScoop, 2026-08-18) since the original March 2025 advisory — roughly two hundred additional organisations identified over the intervening year. On sectors, the only list any of the cited outlets publishes is healthsystemCIO's, which records the figure as spanning every sector the agencies track, including medical, education, legal, insurance and manufacturing. HHS joined as a co-sealer specifically to add the healthcare perspective, describing the Healthcare and Public Health Sector as a frequent victim of Medusa activity (healthsystemCIO, 2026-08-18).

The finding worth carrying into planning is about speed, and it is unusual in being paired with an explicit negative. The agencies state the group exploits "newly announced exploits within 24 hours" and has "been observed to use exploits up to a week before public vulnerability disclosure" — and then rule out the obvious inference: "However, there is no indication Medusa actors develop their own zero-day or N-day vulnerabilities, preferring instead to obtain advanced access to exploits from unknown sources or to quickly leverage newly announced exploits before potential victims can mitigate vulnerabilities through patching" (The Record, 2026-08-18). That combination is the planning fact. An organisation cannot out-wait this actor by assuming a research lead time the group has to fund itself: the pre-disclosure window comes from exploit access obtained somewhere the agencies could not identify, and the 24-hour window comes from acting on the same public advisory the defender is reading. A patch cycle measured in weeks is not a control against it, and the compensating control is exposure reduction on internet-facing software rather than faster patching alone.

The economics of entry are spelled out separately, and are not the same market as the exploit access above — these payments buy a way into a victim network, not a vulnerability. The gang relies on access brokers, "compensating them anywhere from $100 to $1 million, with higher prices going to those who work exclusively with Medusa", while most brokers work simultaneously for multiple ransomware variants (CyberScoop, 2026-08-18); The Record records the same exclusivity premium, noting Medusa "recruits members on cybercriminal forums and offers up to $1 million to initial access brokers who want to work exclusively for the group" (The Record, 2026-08-18). The practical consequence of brokers serving several operations at once is that an access sold into this ecosystem is not tied to one outcome — the same foothold may surface under a different brand.

Post-compromise, the advisory names the tooling rather than bespoke malware. Affiliates deploy credential-stealing tools first, then move to legitimate remote-management software to evade detection: "The FBI said Medusa actors used remote access software AnyDesk, Atera, ConnectWise, eHorus, N-able, BeyondTrust, SimpleHelp and Splashtop" (The Record, 2026-08-18), with Remote Desktop Protocol for lateral movement (CyberScoop, 2026-08-18). Two products from the group's historically exploited list are named, each by a different outlet: CyberScoop records the advisory covering flaws in Fortra's GoAnywhere and BeyondTrust (CyberScoop, 2026-08-18), while healthsystemCIO is the outlet that identifies the February 2026 BeyondTrust disclosure as the advisory's own worked example of how quickly a public disclosure becomes an intrusion (healthsystemCIO, 2026-08-18).

One honest caveat belongs next to the victim count: The Record reports that "Medusa has not added any new victims to its leak site since April", with several experts attributing the pause to law-enforcement attention drawn by an attack on a US medical centre (The Record, 2026-08-18). The 500-plus figure is therefore a record of what happened through April, not evidence of a wave in progress — the advisory's value here is the tradecraft and the tempo, not a current-activity signal.

been observed to use exploits up to a week before public vulnerability disclosure

However, there is no indication Medusa actors develop their own zero-day or N-day vulnerabilities, preferring instead to obtain advanced access to exploits from unknown sources or to quickly leverage newly announced exploits before potential victims can mitigate vulnerabilities through patching

The FBI said Medusa actors used remote access software AnyDesk, Atera, ConnectWise, eHorus, N-able, BeyondTrust, SimpleHelp and Splashtop.

The Record / Recorded Future News 2026-08-18

the victim tally in the advisory jumped from more than 300 to more than 500

CyberScoop 2026-08-18

Medusa has not added any new victims to its leak site since April

The Record / Recorded Future News 2026-08-18
threat19 Aug 05:20Zmulti-sourceOpen finding ↗

2026-08-12 · view entry permalink →

HIGHCVE-2026-18577exploitedupdateNATOB2

UPDATE — the N-central exploitation has an actor and a payload: Microsoft assesses Storm-1175 is behind it, deploying a new ransomware strain called StormEncryptor from the day the flaw was disclosed

UPDATE · originally covered N-able N-central Hotfix 2 (2026.3.1.10) is mandatory even for instances that already applied Hotfix 1 — and the attackers reached the managed endpoints, not just the server (2026-08-09)

the N-able N-central authentication-bypass chain this pipeline has tracked through two hotfixes now has an assessed actor and a named payload. Microsoft Threat Intelligence reported that "the Storm-1175 group began deploying a new ransomware strain on August 2 called StormEncryptor", and that the group is likely exploiting CVE-2026-18577 in N-central to obtain access (The Record, 2026-08-10). The hedge is Microsoft's own and matters: "Microsoft has not formally confirmed the access vector, but noted that StormEncryptor deployments began the same day the flaw was disclosed" (The Record, 2026-08-10). The same-day correlation is the evidence; a confirmed vector is not yet on the record.

The Record describes the actor as financially motivated and linked to China, and its prior activity is why the attribution changes a defender's calculus rather than just labelling it (The Record, 2026-08-10). Microsoft's own April 2026 profile of the group — which does not itself make a China attribution — describes high-tempo Medusa ransomware operations against vulnerable web-facing assets, and records the group moving from initial access to data exfiltration and ransomware deployment often within a few days and in some cases within 24 hours (Microsoft Threat Intelligence, 2026-04-06). Its earlier Medusa victims were healthcare, professional services and finance organisations in Australia, Britain and the United States; StormEncryptor is the departure from that tooling (The Record, 2026-08-10). Note what those sectors and countries describe: the group's previous victim set, not confirmed victims of this campaign, for which no count has been disclosed.

Two facts sharpen the exposure picture for anyone whose managed service provider runs N-central. N-able states it detected the original flaw in a zero-day attack on 31 July, though it is unclear whether the actor behind that first intrusion was Storm-1175 — the initial patch was bypassed, forcing an emergency hotfix on 2 August and a second on 6 August with the warning that the first was not enough. And the patch gap is wide: after the fixes were available, Huntress found more than half of reachable N-central cloud servers across its partner base still unpatched, with 28.6% of self-hosted instances exposed (The Record, 2026-08-10). Huntress went as far as suggesting that anyone running N-central in a higher-risk environment where exposure cannot meaningfully be reduced may need to consider turning the tool off, while cautioning that doing so costs central visibility, patching and remote access when they may be needed most.

The structural point is the one this constituency should carry: a single compromised RMM server is a gateway to every endpoint it manages, so one breach at one provider cascades across its whole client base. The Record draws the direct comparison to the 2021 Kaseya intrusion, where REvil compromised around 60 direct customers and subsequently hit roughly 1,500 downstream businesses, and to the 2024 ScreenConnect attacks — in which Microsoft says Storm-1175 was among the actors targeting the product (The Record, 2026-08-10).

the Storm-1175 group began deploying a new ransomware strain on August 2 called StormEncryptor

Microsoft has not formally confirmed the access vector, but noted that StormEncryptor deployments began the same day the flaw was disclosed.

The Record (Recorded Future News) 2026-08-10
threat12 Aug 04:48Zsingle-sourceOpen finding ↗

2026-06-29 · view entry permalink →

NOTABLE

ESET "Killing me gently" — a de-facto mid-year RaaS-tooling report

Background. The Gentlemen emerged in late 2025 as a RaaS operation founded by "hastalamuerte" (a former Qilin affiliate per Group-IB, previously affiliated with Embargo, LockBit, Medusa and BlackLock per PRODAFT). ESET first hypothesised an in-house EDR-killer in February 2026; Group-IB and Check Point independently corroborated before the gang's own internal data leaked. By April 2026 the group accounted for ~10% of global ransomware activity, and Krebs (06-10) linked the alias to a named individual in Izhevsk, Russia.

ESET's 06-26 deep-dive into the leaked internal data is the most substantive published-in-window documentation of RaaS tooling structure, and reads as a mid-year complement to the W25 Check Point State of Ransomware Q1 2026. Three structural findings a detection engineer should register: (1) GentleKiller is a modular in-house framework with at least eight BYOVD variants, each impersonating a different vendor and abusing a different kernel driver — driver allow-listing alone is insufficient without process-injection-chain detection; (2) the group integrates rival gangs' EDR killers (HexKiller from Warlock, ThrottleBlood shared with MedusaLocker/DragonForce, HavocKiller), so tooling overlap no longer implies operational overlap; (3) victims are selected centrally on FortiGate misconfiguration rather than geography, tying the Gentlemen victim pipeline directly to FortiBleed-style reconnaissance (§ 8). New BYOVD PoCs are operationalised within days of public release. (daily 06-27)

annual-report29 Jun 00:21Zmulti-sourceOpen finding ↗

Earlier coverage (3)