More than 500 critical infrastructure organizations have been compromised by Medusa ransomware as of April 2026, according to a new FBI advisory. The alert, issued jointly by the FBI, CISA, and the Department of Health and Human Services on August 18, marks a sharp escalation from an earlier government warning in March 2025 that reported over 300 critical infrastructure victims as of February 2025. Healthcare facilities have been especially frequent targets, and the ransomware-as-a-service operation has significantly upgraded its attack methods since early 2025.

The advisory details how Medusa has accelerated its exploitation timeline, in some instances deploying exploits within 24 hours after vulnerabilities are publicly announced—before most organizations can install patches. In certain cases, Medusa actors used exploits up to a week before the flaws were publicly disclosed. The group continues to rely on unpatched vulnerabilities as its main entry point and has been characterized as opportunistic, attacking victims with outdated software rather than zeroing in on particular sectors or organizations. There's no evidence Medusa develops its own zero-day or N-day flaws. The ransomware variant first appeared in June 2021 as a closed operation, then shifted to an affiliate model by early 2023 at the latest.

According to the FBI, Medusa actors have enhanced their post-exploitation toolkit with several new stealth and lateral movement techniques. The group now deploys increasingly sophisticated PowerShell obfuscation methods to hide payloads and deletes command line history to erase its tracks. New command-and-control tools include Nezha, an operations and maintenance monitoring platform that gives attackers backdoor visibility into compromised hosts, and GSocket, which lets workstations on separate private networks connect while bypassing firewalls. The advisory notes that Medusa also uses legitimate remote monitoring and management software already present in victim environments to avoid detection, moving laterally through networks and identifying files for theft. Mimikatz harvests credentials by stealing them directly from the LSA authentication mechanism, recording plaintext passwords to a log file. Stolen Active Directory files are particularly dangerous because they can be exploited to forge Kerberos tickets, potentially allowing attackers to impersonate trusted users and traverse an entire domain with fewer barriers.

Nick Tausek, lead security automation architect at Swimlane, warned that Medusa's rapid exploitation creates major challenges for defenders. "Shrinking windows put far more pressure on defenders to identify and remediate exposed systems before Medusa can take advantage," he said. Andrew Costis, engineering manager at AttackIQ, noted the group is blending legitimate remote management tools into operations while deploying new credential theft tactics and bypassing security policies to maintain access. The FBI's guidance urges security teams to focus on incident response, including using threat hunting to scope intrusions, removing command-and-control software like Nezha, deleting local administrator accounts, rotating credentials for service accounts and domain administrators, patching the initial vulnerability, and using CISA's Eviction Strategies Tool to build a systematic removal plan. Medusa employs a double-extortion model, demanding payment both to restore systems and to prevent stolen data from being published online, with ransom notes typically requiring victims to make contact within 48 hours. The compressed response window and evolving tradecraft underscore the growing asymmetry between attacker speed and organizational readiness. Organizations that treat patching as a routine administrative task rather than an urgent defensive priority are effectively volunteering for breach status.