Sentrix

Actor · RaaS · since 2021

Medusa: the RaaS that sells extra days

Identified in June 2021, Medusa had hit over 500 victims by April 2026 per CISA and is a top three ransomware threat to Canada. Access, incidents and controls.

Model
RaaS · since 2021-06
Ways in
Initial access brokers · Phishing · ScreenConnect CVE-2024-1709 · Fortinet EMS CVE-2023-48788 · GoAnywhere CVE-2025-10035
Targets
Healthcare · Education · Legal and insurance · Technology · Critical infrastructure
Official advisories
AA25-071A

By Sentrix · Published 2026-09-20

Medusa built an extortion mechanism that is cynical by design: a public countdown, a price to extend it, another to delete the data. Behind the theatre sits an operation that exploits the vulnerability of the day on anything exposed to the internet.

Who they are

Joint advisory AA25-071A from the FBI, CISA and MS-ISAC, published on March 12, 2025 and updated on August 18, 2026, identifies Medusa as a ransomware-as-a-service first seen in June 2021. First operated as a closed variant, it has sold its service since at least early 2023 to affiliates granted varying levels of trust, while keeping negotiation under the developers' control for less experienced affiliates. As of April 2026, according to the same advisory, developers and affiliates had impacted over 500 victims across critical infrastructure sectors.

Unit 42 documented the turn to public extortion: the Medusa Blog leak site launched in early 2023, and Unit 42 counted approximately 74 organizations impacted worldwide in 2023. The Canadian Centre for Cyber Security, in its 2025-2027 outlook of January 28, 2026, lists Medusa among the top three ransomware threats to Canada in 2024, with Akira and Play, and notes victims among critical infrastructure organizations and the information and communications technology sector in Canada.

How they get in

Advisory AA25-071A describes two main routes: phishing campaigns and exploitation of unpatched vulnerabilities, including CVE-2024-1709 on ConnectWise ScreenConnect, CVE-2023-48788 on Fortinet EMS, CVE-2025-10035 on Fortra GoAnywhere and CVE-2026-1731 on BeyondTrust. The developers recruit initial access brokers with payments between 100 and 1 million US dollars and the option of working exclusively for Medusa, again according to the advisory.

On April 6, 2026, Microsoft published a profile of the actor Storm-1175, which deploys Medusa at high tempo by exploiting freshly disclosed vulnerabilities, up to SAP NetWeaver CVE-2025-31324 weaponized within a day, then settles in with legitimate remote management tools such as Atera, MeshAgent or SimpleHelp and exfiltrates with Rclone. Inside, advisory AA25-071A cites Mimikatz, PsExec, Ligolo-ng and Cloudflared. Double extortion is topped by a countdown on the leak site: Unit 42 and advisory AA25-071A report that one extra day costs 10,000 US dollars.

What they have done

  • Early 2023: launch of the Medusa Blog leak site and the shift to public extortion, documented by Unit 42, with approximately 74 organizations impacted worldwide in 2023.
  • March 12, 2025: publication of advisory AA25-071A, prompted by the volume of attacks on critical infrastructure.
  • 2025 and 2026: Storm-1175 campaigns described by Microsoft, exploiting SimpleHelp, CrushFTP, GoAnywhere, SmarterMail and BeyondTrust within days of disclosure.
  • April 2026: over 500 cumulative victims according to the update of advisory AA25-071A, along with a case of a victim contacted after payment for a second ransom.

What stops them

The mitigations of advisory AA25-071A and Microsoft, mapped to the frameworks auditors check.

  1. Patch exposed assets in days, not months: remote management tools, file transfer, mail, gateways. An external attack surface inventory keeps that list manageable. ISO 27001:2022 A.8.8 and A.5.9, SOC 2 CC7.1.
  2. Phishing-resistant MFA on webmail, VPN and remote management tool accounts. ISO 27001:2022 A.8.5, SOC 2 CC6.1.
  3. Remote access only through a VPN or jump host and monitoring of unauthorized scanning. ISO 27001:2022 A.8.20 and A.8.16, SOC 2 CC6.6.
  4. Encrypted, immutable backups with a proven recovery plan. ISO 27001:2022 A.8.13, SOC 2 A1.2.
  5. Control of remote management tools: allowlist of approved agents, alert on any new Atera, MeshAgent, AnyDesk or SimpleHelp. ISO 27001:2022 A.8.19.
  6. Account audits and credential rotation, to strip the value from what access brokers sell. ISO 27001:2022 A.5.17 and A.5.18, SOC 2 CC6.2.

Sources

Frequently asked questions

Medusa, MedusaLocker, Medusa Stealer: the same actor?
No. Advisory AA25-071A states that Medusa is unrelated to MedusaLocker and to the Medusa mobile malware. The Medusa described here is a ransomware-as-a-service identified in June 2021, first operated as a closed variant, then opened to affiliates since at least early 2023, while keeping negotiation under the developers' control for less experienced affiliates.
What does triple extortion mean with Medusa?
The leak site shows a countdown per victim. According to advisory AA25-071A, the victim can pay 10,000 US dollars in cryptocurrency to add a day to the timer. The advisory also reports a victim contacted after payment by an actor claiming the negotiator had stolen the ransom and demanding half the amount again, which suggests a triple-extortion scheme or operational dysfunction.
How fast does Medusa move from intrusion to encryption?
Fast. In April 2026 Microsoft described the actor Storm-1175, which exploits freshly disclosed vulnerabilities on web-facing systems and moves from initial access to exfiltration and Medusa deployment within a few days, in some cases within twenty-four hours. A monthly patch cycle cannot keep that pace on exposed assets, which is why exposure management matters here.

Let's talk about your compliance program.

Last updated: 2026-09-20