MEDUSA

RANSOMWARE

MEDUSA is primarily focused on targeting Managed Service Providers (MSPs) and their associated Remote Management and Monitoring (RMM) solutions, exploiting vulnerabilities within these systems to gain initial access. The group leverages phishing tactics such as T1566 Phishing to deliver malware like Advanced IP Scanner and AnyDesk, which are commonly used for remote administration. Once inside the network, MEDUSA employs a range of sophisticated techniques including lateral movement with Windows Management Instrumentation (WMI) and credential harvesting via Valid Accounts (T1078). They typically engage in double extortion by exfiltrating data before encrypting it to maximize their leverage over victims.

From a technical standpoint, MEDUSA exploits critical vulnerabilities such as CVE-2024-57727 within RMM solutions like SimpleHelp, indicating a preference for targeting software with high privilege access. The group's use of tools like Cloudflared and Ligolo suggests an advanced understanding of network infrastructure and evasion techniques. Defenders should prioritize patching critical vulnerabilities in RMM products and enhancing phishing detection mechanisms to mitigate the risk posed by MEDUSA’s sophisticated attack vectors.

CISA Intelligence #StopRansomware

#StopRansomware: Medusa Ransomware · 2026-08-18

Staying Secure at Eventsno-cost Cyber ServicesCybersecurity Awareness MonthKnown Exploited Vulnerabilities CatalogReport A Cyber Issue

Close Topics Topics Cybersecurity Best Practices Cyber Threats and Response Critical Infrastructure Security and Resilience Election Security Emergency Communications Industrial Control Systems Information and Communications Technology Supply Chain Security Partnerships and Collaboration Physical Security Risk Management How can we help? GovernmentEducational InstitutionsIndustryState, Local, Tribal, and TerritorialIndividuals and FamiliesSmall and Medium BusinessesFind Help LocallyFaith-Based CommunityExecutivesHigh-Risk Communities Spotlight Resources & Tools Resources & Tools All Resources & Tools Services Programs Resources Training Groups News & Events News & Events Directives News Events Cybersecurity Alerts & Advisories Request a CISA Speaker Congressional Testimony CISA Conferences CISA Live! Careers Careers Benefits & Perks Hiring and Recruitment New Employee Orientation & Onboarding Students & Recent Graduates Veteran and Military Spouses About About Divisions & Offices Regions Leadership Doing Business with CISA Site Links CISA GitHub CISA Central Contact Us Subscribe Transparency and Accountability Policies & Plans Staying Secure at Eventsno-cost Cyber ServicesCybersecurity Awareness MonthKnown Exploited Vulnerabilities CatalogReport A Cyber Issue

#StopRansomware: MedusaLocker · 2022-08-11

Staying Secure at Eventsno-cost Cyber ServicesCybersecurity Awareness MonthKnown Exploited Vulnerabilities CatalogReport A Cyber Issue

Close Topics Topics Cybersecurity Best Practices Cyber Threats and Response Critical Infrastructure Security and Resilience Election Security Emergency Communications Industrial Control Systems Information and Communications Technology Supply Chain Security Partnerships and Collaboration Physical Security Risk Management How can we help? GovernmentEducational InstitutionsIndustryState, Local, Tribal, and TerritorialIndividuals and FamiliesSmall and Medium BusinessesFind Help LocallyFaith-Based CommunityExecutivesHigh-Risk Communities Spotlight Resources & Tools Resources & Tools All Resources & Tools Services Programs Resources Training Groups News & Events News & Events Directives News Events Cybersecurity Alerts & Advisories Request a CISA Speaker Congressional Testimony CISA Conferences CISA Live! Careers Careers Benefits & Perks Hiring and Recruitment New Employee Orientation & Onboarding Students & Recent Graduates Veteran and Military Spouses About About Divisions & Offices Regions Leadership Doing Business with CISA Site Links CISA GitHub CISA Central Contact Us Subscribe Transparency and Accountability Policies & Plans Staying Secure at Eventsno-cost Cyber ServicesCybersecurity Awareness MonthKnown Exploited Vulnerabilities CatalogReport A Cyber Issue

Confirmed CVEs (1)

Exploited by this group as confirmed by threat intelligence sources.

CVE-2024-57727 CRITICAL SimpleHelp SimpleHelp 9.1

Predicted CVEs (8) CORRELATION

How does prediction work?

Predicted CVEs are identified through automated correlation using multiple sources: vendor/product profiles historically targeted by the group (MITRE ATT&CK), attack chain patterns (KEV + TTPs), threat intelligence (MISP, STIX), and AI analysis. These CVEs have not been confirmed as exploited by this specific group, but have a high probability of being targets based on the actor's operational profile.

CVE-2024-1709 CRITICAL ConnectWise ScreenConnect high 10.0 CVE-2024-1709 CRITICAL ConnectWise ScreenConnect predicted 10.0 CVE-2024-57726 CRITICAL SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role. predicted 9.9 CVE-2023-48788 CRITICAL Fortinet FortiClientEMS high 9.8 CVE-2023-48788 CRITICAL Fortinet FortiClientEMS predicted 9.8 CVE-2024-57727 CRITICAL SimpleHelp SimpleHelp predicted 9.1 CVE-2024-1708 HIGH ConnectWise ScreenConnect predicted 8.4 CVE-2024-57728 HIGH SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user. predicted 7.2

ATT&CK Techniques (19)

T1078 Valid Accounts Initial Access T1133 External Remote Services Initial Access T1566 Phishing Initial Access T1047 Windows Management Instrumentation Execution T1059 Command and Scripting Interpreter Execution T1562 Impair Defenses Defense Evasion T1562.001 Disable or Modify Tools Defense Evasion T1562.009 Safe Mode Boot Defense Evasion T1110 Brute Force Credential Access T1083 File and Directory Discovery Discovery T1135 Network Share Discovery Discovery T1021 Remote Services Lateral Movement T1045 Exfiltration Over C2 Channel Exfiltration T1048 Exfiltration Over Alternative Protocol Exfiltration T1567 Exfiltration Over Web Service Exfiltration T1105 Ingress Tool Transfer Command and Control T1486 Data Encrypted for Impact Impact T1489 Service Stop Impact T1490 Inhibit System Recovery Impact