CISA, the FBI, and HHS updated advisory AA25-071A on August 18, 2026, covering the Medusa ransomware operation, which has surpassed 500 victims from June 2021 through April 2026. More than 200 organizations were added to the tally in the last year alone, with a marked acceleration against healthcare and critical infrastructure. What sets Medusa apart from other groups is not exploit sophistication but the speed at which it weaponizes them: within 24 hours of public disclosure, and in some cases a week in advance.
- The updated CISA/FBI/HHS advisory dated August 18, 2026 documents over 500 Medusa victims since June 2021, with 200 new ones in the prior year alone.
- The group exploits freshly disclosed vulnerabilities within 24 hours, without developing its own zero-days; in some cases it used exploits a week before publication.
- Medusa has operated as a Ransomware-as-a-Service since 2023, recruiting initial access brokers with payments ranging from $100 to $1,000,000.
- Symantec detected that operators of the North Korean Lazarus/Stonefly group have used Medusa, though it does not emerge whether all victims were hit by Pyongyang-linked actors.
Speed as Strategy: Why the "Patching Gap" Is Enough for Medusa
Medusa does not develop its own vulnerabilities. According to the joint advisory, "there is no indication that Medusa operators develop zero-day or N-day exploits, preferring to obtain early access to exploits from unknown sources or rapidly exploit newly announced exploits." This attack architecture offers a clear operational advantage: it offloads the cost of vulnerability research to others and monetizes the window between disclosure and mitigation.
The mechanism is measurable. CISA documents that Medusa weaponizes CVEs within 24 hours of publication. In some cases, the group operated with a week's lead. The leading hypothesis is access to pre-release exploits through brokers or criminal networks, but the exact origin remains unidentified. The use of Interactsh dynamic URLs to verify exploitation success confirms a rapid, structured technical validation process.
The RaaS model adopted in 2023 amplifies this capability. Medusa recruits affiliates on criminal forums, offering $100 to $1,000,000 for initial access, with a premium for exclusivity. The affiliate earns a share of the ransom; Medusa runs the negotiation platform and leak site. This division of labor enables scaling without proportionally increasing internal technical staff.
Five Critical CVEs and Healthcare Targeting
The exploited vulnerabilities documented in the advisory are all rated critical with maximum CVSS scores. CVE-2024-1709 (ConnectWise ScreenConnect) scores 10.0 per NVD; CVE-2023-48788 (Fortinet EMS) is rated 9.8; CVE-2025-10035 (Fortra GoAnywhere) carries CVSS 10.0; CVE-2026-1731 (BeyondTrust PRA) is classified 9.8. These are remote access and endpoint management technologies, consistent with Medusa's preference for RMM tools already present in the target network or installed anew.
The full list of RMM tools used for lateral movement and persistence includes AnyDesk, Atera, ConnectWise, BeyondTrust, Splashtop, SimpleHelp, eHorus, and N-able, per FBI data in the CISA dossier. The technique is known: abuse legitimate platforms already authorized by the firewall to evade network controls. This is supplemented by credential dumping via comsvcs.dll on LSASS, PowerShell obfuscation, and the use of Rclone in folders excluded from Windows Defender.
The Healthcare and Public Health sector has been "frequently targeted," in the advisory's words. The most striking incident is the April 2026 attack on the University of Mississippi Medical Center, which caused the outage of the state's only pediatric hospital, sole Level I trauma center, and sole Level IV NICU. After this event, Medusa stopped adding victims to its leak site. The source hypothesizes a deterrence effect from law enforcement, but the exact reason is unconfirmed.
"Medusa actors leverage newly announced exploits within 24 hours"
— CISA/FBI/HHS, advisory AA25-071A
Immediate Actions
Priority actions derive directly from the TTPs documented in the advisory and FBI forensic analysis.
1. Compress the patching cycle to under 24 hours for remote access technologies. The documented CVEs hit ScreenConnect, Fortinet EMS, GoAnywhere, and BeyondTrust PRA: products that manage privileged sessions and are often internet-exposed. Automated patching or perimeter virtual patching are necessary when the attack vector activates before the vendor releases a fix.
2. Inventory and control RMM tools present on the network. Medusa installs or abuses AnyDesk, Atera, ConnectWise, BeyondTrust, Splashtop, SimpleHelp, eHorus, and N-able. Every unauthorized or uninventoried instance is a potential lateral movement channel. Organizations must treat RMM as critical assets, with explicit approval and installation monitoring.
3. Segment networks with remote access and limit exposure of endpoint management services. The vulnerabilities exploited by Medusa are typically WAN-accessible. Restricting access to VPN with phishing-resistant MFA, and segmenting segments holding healthcare or critical data, reduce the attack surface even when patching is not immediate.
4. Implement immutable offline backups and test recovery procedures. Medusa operates a double-extortion model: encryption and exfiltration. The ability to restore without relying on the group's decryptors reduces negotiating pressure. CISA stresses there is no verification that data is actually deleted after payment.
The Geopolitical Dimension: Lazarus, Stonefly, and Espionage Funding
Symantec, through its Threat Hunter Team, has "detected evidence" that operators of the North Korean Lazarus/Stonefly group have used the Medusa ransomware. The intelligence includes a successful attack in the Middle East and a failed attempt against a U.S. healthcare target. Symantec provides specific hash IOCs for correlation.
The finding introduces a layer of complexity: the average ransom demanded by Medusa was approximately $260,000 according to Symantec, with payments handled through individual negotiation. If North Korean state actors participate in the affiliate program, proceeds could fund espionage operations beyond financial crime. However, Symantec specifies that "it is not known whether all victims were hit by North Korean operators." No infrastructure overlaps systematically linking Medusa to Lazarus have emerged to date.
The Adversary's Tempo and the Limits of Traditional Defenses
The CISA update of August 18, 2026 paints an operational profile that challenges the average defensive organization. Medusa does not compete on vulnerability research but on reaction: a model that externalizes R&D cost and internalizes the profit of speed. The 500 victims in five years, with 200 concentrated in the last year, indicate the RaaS transition worked as a scalability lever.
The message for defenders is not that patches don't work, but that vulnerability management cycles designed on week-long windows are incompatible with an adversary that measures success in hours. The issue is not solely technical: it is one of process, automation, and accepting that patching will always lag behind weaponization.
The case of the Mississippi pediatric hospital shows where this asymmetry leads. When the only center of that level for an entire state is taken down by a group that discovered not a single vulnerability of its own, the problem to solve is not in the code. It is in the time between knowledge of the flaw and its effective removal.
Sources
- https://therecord.media/more-than-200-medusa-ransomware-victims-in-last-year-cisa
- https://mallory.ai/stories/01a01613-ecfe-7a7a-aedb-780ab93bc378
- https://cyberscoop.com/medusa-ransomware-tactics-cisa-advisory/
- https://cybermagazine.com/news/how-medusa-ransomware-gang-attacked-500-critical-companies
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-071a
- https://www.security.com/threat-intelligence/lazarus-medusa-ransomware
- https://mallory.ai/intelligence
Information verified against cited sources and current as of publication.