MEDUSA

RANSOMWARE

MEDUSA is primarily focused on targeting Managed Service Providers (MSPs) and their associated Remote Management and Monitoring (RMM) solutions, exploiting vulnerabilities within these systems to gain initial access. The group leverages phishing tactics such as T1566 Phishing to deliver malware like Advanced IP Scanner and AnyDesk, which are commonly used for remote administration. Once inside the network, MEDUSA employs a range of sophisticated techniques including lateral movement with Windows Management Instrumentation (WMI) and credential harvesting via Valid Accounts (T1078). They typically engage in double extortion by exfiltrating data before encrypting it to maximize their leverage over victims.

From a technical standpoint, MEDUSA exploits critical vulnerabilities such as CVE-2024-57727 within RMM solutions like SimpleHelp, indicating a preference for targeting software with high privilege access. The group's use of tools like Cloudflared and Ligolo suggests an advanced understanding of network infrastructure and evasion techniques. Defenders should prioritize patching critical vulnerabilities in RMM products and enhancing phishing detection mechanisms to mitigate the risk posed by MEDUSA’s sophisticated attack vectors.

CISA Intelligence #StopRansomware

#StopRansomware: Medusa Ransomware · 2026-08-18

Staying Secure at Eventsno-cost Cyber ServicesCybersecurity Awareness MonthKEV CatalogReport A Cyber Issue

Close Topics Topics Cybersecurity Best Practices Cyber Threats and Response Critical Infrastructure Security and Resilience Election Security Emergency Communications Industrial Control Systems Information and Communications Technology Supply Chain Security Partnerships and Collaboration Physical Security Risk Management How can we help? GovernmentEducational InstitutionsIndustryState, Local, Tribal, and TerritorialIndividuals and FamiliesSmall and Medium BusinessesFind Help LocallyFaith-Based CommunityExecutivesHigh-Risk Communities Spotlight Resources & Tools Resources & Tools All Resources & Tools Services Programs Resources Training Groups News & Events News & Events Directives News Events Cybersecurity Alerts & Advisories Request a CISA Speaker Congressional Testimony CISA Conferences CISA Live! Careers Careers Benefits & Perks Hiring and Recruitment New Employee Orientation & Onboarding Students & Recent Graduates Veteran and Military Spouses About About Divisions & Offices Regions Leadership Doing Business with CISA Site Links CISA GitHub CISA Central Contact Us Subscribe Transparency and Accountability Policies & Plans Staying Secure at Eventsno-cost Cyber ServicesCybersecurity Awareness MonthKEV CatalogReport A Cyber Issue

#StopRansomware: MedusaLocker · 2022-08-11

Staying Secure at Eventsno-cost Cyber ServicesCybersecurity Awareness MonthKEV CatalogReport A Cyber Issue

Close Topics Topics Cybersecurity Best Practices Cyber Threats and Response Critical Infrastructure Security and Resilience Election Security Emergency Communications Industrial Control Systems Information and Communications Technology Supply Chain Security Partnerships and Collaboration Physical Security Risk Management How can we help? GovernmentEducational InstitutionsIndustryState, Local, Tribal, and TerritorialIndividuals and FamiliesSmall and Medium BusinessesFind Help LocallyFaith-Based CommunityExecutivesHigh-Risk Communities Spotlight Resources & Tools Resources & Tools All Resources & Tools Services Programs Resources Training Groups News & Events News & Events Directives News Events Cybersecurity Alerts & Advisories Request a CISA Speaker Congressional Testimony CISA Conferences CISA Live! Careers Careers Benefits & Perks Hiring and Recruitment New Employee Orientation & Onboarding Students & Recent Graduates Veteran and Military Spouses About About Divisions & Offices Regions Leadership Doing Business with CISA Site Links CISA GitHub CISA Central Contact Us Subscribe Transparency and Accountability Policies & Plans Staying Secure at Eventsno-cost Cyber ServicesCybersecurity Awareness MonthKEV CatalogReport A Cyber Issue

Actions to take today to mitigate cyber threats from ransomware:• Prioritize remediating known exploited vulnerabilities.• Train users to recognize and report phishing attempts.• Enable and enforce multifactor authentication.

Confirmed CVEs (2)

Exploited by this group as confirmed by threat intelligence sources.

CVE-2026-1731 CRITICAL BeyondTrust Remote Support(RS) & Privileged Remote Access(PRA) 9.8 CVE-2024-57727 HIGH SimpleHelp SimpleHelp 7.5

Predicted CVEs (30) CORRELATION

How does prediction work?

Predicted CVEs are identified through automated correlation using multiple sources: vendor/product profiles historically targeted by the group (MITRE ATT&CK), attack chain patterns (KEV + TTPs), threat intelligence (MISP, STIX), and AI analysis. These CVEs have not been confirmed as exploited by this specific group, but have a high probability of being targets based on the actor's operational profile.

CVE-2024-1709 CRITICAL ConnectWise ScreenConnect high 10.0 CVE-2024-1709 CRITICAL ConnectWise ScreenConnect predicted 10.0 CVE-2021-44228 CRITICAL Apache Software Foundation Apache Log4j2 low 10.0 CVE-2026-20079 CRITICAL Cisco Secure Firewall Management Center (FMC) low 10.0 CVE-2026-20131 CRITICAL Cisco Secure Firewall Management Center (FMC) predicted 10.0 CVE-2021-44228 CRITICAL Apache Software Foundation Apache Log4j2 predicted 10.0 CVE-2024-57726 CRITICAL SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role. predicted 9.9 CVE-2026-1731 CRITICAL BeyondTrust Remote Support(RS) & Privileged Remote Access(PRA) predicted 9.8 CVE-2023-48788 CRITICAL Fortinet FortiClientEMS high 9.8 CVE-2023-48788 CRITICAL Fortinet FortiClientEMS predicted 9.8 CVE-2021-45046 CRITICAL Apache Software Foundation Apache Log4j predicted 9.0 CVE-2021-45046 CRITICAL Apache Software Foundation Apache Log4j low 9.0 CVE-2026-73570 HIGH Zimbra Collaboration low 8.9 CVE-2021-34527 HIGH Microsoft Windows 10 Version 1809 predicted 8.8 CVE-2024-1708 HIGH ConnectWise ScreenConnect predicted 8.4 CVE-2024-21412 HIGH Microsoft Windows 11 version 21H2 predicted 8.1 CVE-2021-1675 HIGH Microsoft Windows 10 Version 1809 predicted 7.8 CVE-2024-26169 HIGH Microsoft Windows 10 Version 1809 predicted 7.8 CVE-2022-30190 HIGH Microsoft Windows 10 Version 1809 low 7.8 CVE-2023-28252 HIGH Microsoft Windows 10 Version 1809 predicted 7.8 CVE-2022-30190 HIGH Microsoft Windows 10 Version 1809 predicted 7.8 CVE-2020-0787 HIGH Microsoft Windows predicted 7.8 CVE-2021-36942 HIGH Microsoft Windows Server 2019 predicted 7.5 CVE-2023-36884 HIGH Microsoft Windows 10 Version 1809 predicted 7.5 CVE-2024-57727 HIGH SimpleHelp SimpleHelp predicted 7.5 CVE-2024-57728 HIGH SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user. predicted 7.2 CVE-2021-43890 HIGH Microsoft App Installer predicted 7.1 CVE-2022-41091 MEDIUM Microsoft Windows 10 Version 1809 predicted 5.4 CVE-2026-20316 MEDIUM Cisco Secure Firewall Management Center (FMC) predicted 5.3 CVE-2026-20316 MEDIUM Cisco Secure Firewall Management Center (FMC) low 5.3

ATT&CK Techniques (77)

T1078 Valid Accounts Initial Access T1133 External Remote Services Initial Access T1190 Exploit Public-Facing Application Initial Access T1566 Phishing Initial Access T1047 Windows Management Instrumentation Execution T1059 Command and Scripting Interpreter Execution T1059.001 Command and Scripting Interpreter: PowerShell Execution T1059.003 Command and Scripting Interpreter: Windows Command Shell Execution T1106 Native API Execution T1559.001 Inter-Process Communication: Component Object Model Execution T1569.002 System Services: Service Execution Execution T1675 ESXi Administration Command Execution T1136.002 Create Account: Domain Account Persistence T1505.003 Server Software Component: Web Shell Persistence T1484.001 Domain or Tenant Policy Modification: Group Policy Modification Privilege Escalation T1543.003 Create or Modify System Process: Windows Service Privilege Escalation T1548.002 Abuse Elevation Control Mechanism: Bypass User Account Control Privilege Escalation T1006 Direct Volume Access Stealth T1027 Obfuscated Files or Information Stealth T1027.002 Obfuscated Files or Information: Software Packing Stealth T1027.010 Obfuscated Files or Information: Command Obfuscation Stealth T1027.013 Obfuscated Files or Information: Encrypted/Encoded File Stealth T1070 Indicator Removal Stealth T1070.003 Indicator Removal: Clear Command History Stealth T1070.004 Indicator Removal: File Deletion Stealth T1218.014 System Binary Proxy Execution: MMC Stealth T1562 Impair Defenses Defense Evasion T1562.001 Disable or Modify Tools Defense Evasion T1562.009 Safe Mode Boot Defense Evasion T1564.003 Hide Artifacts: Hidden Window Stealth T1564.012 Hide Artifacts: File/Path Exclusions Stealth T1003.001 OS Credential Dumping: LSASS Memory Credential Access T1003.003 OS Credential Dumping: NTDS Credential Access T1110 Brute Force Credential Access T1558 Steal or Forge Kerberos Tickets Credential Access T1016 System Network Configuration Discovery Discovery T1018 Remote System Discovery Discovery T1033 System Owner/User Discovery Discovery T1046 Network Service Discovery Discovery T1049 System Network Connections Discovery Discovery T1057 Process Discovery Discovery T1069.002 Permission Groups Discovery: Domain Groups Discovery T1082 System Information Discovery Discovery T1083 File and Directory Discovery Discovery T1087.001 Account Discovery: Local Account Discovery T1135 Network Share Discovery Discovery T1518.001 Software Discovery: Security Software Discovery Discovery T1652 Device Driver Discovery Discovery T1021 Remote Services Lateral Movement T1021.001 Remote Services: Remote Desktop Protocol Lateral Movement T1072 Software Deployment Tools Lateral Movement T1570 Lateral Tool Transfer Lateral Movement T1045 Exfiltration Over C2 Channel Exfiltration T1048 Exfiltration Over Alternative Protocol Exfiltration T1567 Exfiltration Over Web Service Exfiltration T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage Exfiltration T1071.001 Application Layer Protocol: Web Protocols Command and Control T1090.003 Proxy: Multi-hop Proxy Command and Control T1105 Ingress Tool Transfer Command and Control T1219 Remote Access Tools Command and Control T1573.002 Encrypted Channel: Asymmetric Cryptography Command and Control T1486 Data Encrypted for Impact Impact T1489 Service Stop Impact T1490 Inhibit System Recovery Impact T1529 System Shutdown/Reboot Impact T1657 Financial Theft Impact T1583.006 Acquire Infrastructure: Web Services Resource Development T1585.001 Establish Accounts: Social Media Accounts Resource Development T1585.002 Establish Accounts: Email Accounts Resource Development T1588.002 Obtain Capabilities: Tool Resource Development T1608.002 Stage Capabilities: Upload Tool Resource Development T1650 Acquire Access Resource Development T1112 Modify Registry Defense Impairment T1553.002 Subvert Trust Controls: Code Signing Defense Impairment T1685 Disable or Modify Tools Defense Impairment T1686 Disable or Modify System Firewall Defense Impairment T1690 Prevent Command History Logging Defense Impairment