2026-08-19NOTABLEA ransomware crew that develops no zero-days still beats the patch window, on exploits it obtains from sources the agencies cannot identify
Medusa
malware · malware:medusa single-source
Ransomware-as-a-service operation that emerged in 2021 as a closed group and moved to an affiliate model in 2023, tracked by CISA, the FBI and HHS in the joint #StopRansomware advisory AA25-071A. The 2026-08-18 update, carrying FBI investigative data through April 2026, raised the recorded victim count from more than 300 to more than 500; the only sector list the cited reporting carries covers medical, education, legal, insurance and manufacturing. The agencies state affiliates exploit newly announced vulnerabilities within 24 hours and have been observed using exploits up to a week before public disclosure while developing no zero-day or N-day flaws of their own, obtaining that exploit access from sources the agencies could not identify. Separately from exploit access, initial-access brokers who sell entry into victim networks are paid between $100 and $1 million with a premium for exclusivity; post-compromise the affiliates use legitimate remote-management software and RDP rather than bespoke tooling. The group had added no new leak-site victims since April at the time of the update (CyberScoop and The Record, both 2026-08-18). Distinct from the unrelated MedusaLocker and MedusaHVNC families already tracked in this registry.
Coverage
4
1 about it · 3 mentions · first 2026-06-21 → last 2026-09-07
Latest activity
2026-08-19
A ransomware crew that develops no zero-days still beats the patch window, on exploits it obtains from…
Peak priority
notable
1 notable
Targets
healthcare
sectors: healthcare, education, legal-services · regions: us, europe
Sources cited
15
13 hosts
Defender insights
What each entry about Medusa tells a defender to do, newest first.
Triage
Story timeline
Every entry that names Medusa, newest first. Rows tagged mention only name it in passing: they are listed for completeness and add nothing to the action items, pivots or ATT&CK profile on this page.
- 2026-09-07Recorded Future's H1 2026 Malware and Vulnerability Trends: two clusters reuse an identical post-exploitation tool stack across thirteen and ten unrelated initial CVEs
- 2026-08-19Medusa's joint advisory update puts a number on the patch race: affiliates weaponise newly announced flaws within 24 hours, and the agencies find no sign the group develops any of them itself
- 2026-08-03CVE-2026-18556 / CVE-2026-18577, N-able N-central: unauthenticated admin access to the RMM console, exploited in the wild, and the day-one fix was itself bypassable
- 2026-06-21HCRG Care Group first notifies patients of a February 2025 Medusa breach, 16 months on
Hunting pivots
ATT&CK techniques (5 across 7 tactics)
5 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessValid Accounts · Exploit Public-Facing Application
- PersistenceValid Accounts
- Privilege EscalationValid Accounts
- StealthValid Accounts
- Lateral MovementRemote Services: Remote Desktop Protocol
- Command and ControlRemote Access Tools
- ImpactData Encrypted for Impact
Initial Access TA0001
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-08-19/medusa-raas-advisory-update-24-hour-weaponisation · ATT&CK page ↗
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-08-19/medusa-raas-advisory-update-24-hour-weaponisation · ATT&CK page ↗
Persistence TA0003
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-08-19/medusa-raas-advisory-update-24-hour-weaponisation · ATT&CK page ↗
Privilege Escalation TA0004
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-08-19/medusa-raas-advisory-update-24-hour-weaponisation · ATT&CK page ↗
Stealth TA0005
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-08-19/medusa-raas-advisory-update-24-hour-weaponisation · ATT&CK page ↗
Lateral Movement TA0008
T1021.001Remote Services: Remote Desktop Protocol×1
Adversaries may use Valid Accounts to log into a computer using the Remote Desktop Protocol (RDP). The adversary may then perform actions as the logged-on user.
Evidence: 2026-08-19/medusa-raas-advisory-update-24-hour-weaponisation · ATT&CK page ↗
Command and Control TA0011
T1219Remote Access Tools×1
An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network. Remote access tools create a session between two trusted hosts through a graphical interface, a command line interaction, a protocol tunnel via development or management software, or hardware-level access such as KVM (Keyboard, Video, Mouse) over IP solutions. Desktop support software (usually graphical interface) and remote management software (typically command line interface) allow a user to control a computer remotely as if they are a local user inheriting the user or software permissions. This software is commonly used for troubleshooting, software installation, and system management. Adversaries may similarly abuse response features included in EDR and other defensive tools that enable remote access.
Evidence: 2026-08-19/medusa-raas-advisory-update-24-hour-weaponisation · ATT&CK page ↗
Impact TA0040
T1486Data Encrypted for Impact×1
Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.
Evidence: 2026-08-19/medusa-raas-advisory-update-24-hour-weaponisation · ATT&CK page ↗
Entries about Medusa (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- N-able N-central×1
- N-able N-central, authentication bypass using an alternate path or channel (CWE-288), affects through 2026.1, fixed in 2026.2 (CVSS 8.2) | CISA KEV 2026-08-04.×1
- N-able N-central, incomplete patch for CVE-2026-18556; unauthenticated admin auth bypass exploited in the wild, superseded by Hotfix 2 build 2026.3.1.10 of 2026-08-06, which the vendor requires even where 2026.3.1.7 was applied (CVSS 8.2)×1
- PhantomKiller×1
- Storm-1175×1
- StormEncryptor×1
Where this entity is cited
Source distribution
- status.n-able.com2 (13%)
- therecord.media2 (13%)
- cisa.gov1 (7%)
- cyberscoop.com1 (7%)
- healthsystemcio.com1 (7%)
- hipaapulse.com1 (7%)
- huntress.com1 (7%)
- microsoft.com1 (7%)
- other5 (33%)
All cited sources (15)
- cisa.govCISAhttps://www.cisa.gov/news-events/alerts/2026/08/04/cisa-adds-three-known-exploited-vulnerabilities-catalog
- cyberscoop.comCyberScoophttps://cyberscoop.com/medusa-ransomware-tactics-cisa-advisory/
- healthsystemcio.comhealthsystemCIOhttps://healthsystemcio.com/2026/08/18/medusa-ransomware-advisory-hhs/
- hipaapulse.comHIPAA Pulsehttps://hipaapulse.com/uk-more-than-one-year-later-hcrg-is-first-notifying-patients-of-33ec763c
- huntress.comHuntresshttps://www.huntress.com/blog/n-able-vulnerability-exploitation
- microsoft.comMicrosoft Threat Intelligencehttps://www.microsoft.com/en-us/security/blog/2026/04/06/storm-1175-focuses-gaze-on-vulnerable-web-facing-assets-in-high-tempo-medusa-ransomware-operations/
- n-able.comN-ablehttps://www.n-able.com/blog/n-central-security-update-august-2-2026
- recordedfuture.comRecorded Future (Insikt Group)https://www.recordedfuture.com/research/h1-2026-malware-vulnerability-trends
- securelist.comKaspersky Securelist (GReAT)https://securelist.com/strikeshark-campaign/120326/
- sophos.comSophos X-Ops (Counter Threat Unit)https://www.sophos.com/en-us/blog/nable-ncentral-exploitation-results-in-rmm-tool-deployment
- status.n-able.comN-able status pagehttps://status.n-able.com/2026/08/02/n-central-2026-3-hotfix-1-mitigation-for-cve-2026-18577/
- status.n-able.comN-ablehttps://status.n-able.com/2026/08/06/n-central-2026-3-hotfix-2-additional-mitigation-for-cve-2026-18577/
- thehackernews.comThe Hacker Newshttps://thehackernews.com/2026/08/n-central-attackers-reach-managed.html
- therecord.mediaThe Record (Recorded Future News)https://therecord.media/china-hackers-ransomware-microsoft
- therecord.mediaThe Record / Recorded Future Newshttps://therecord.media/more-than-200-medusa-ransomware-victims-in-last-year-cisa