Medusa Ransomware Threaters Steal Data Disable Security Tools and Encrypt Networks

In a joint advisory issued by the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the U.S. Department of Health and Human Services (HHS), a new wave of ransomware activity has been identified. The threat actors, operating under the moniker Medusa, have been actively targeting enterprise environments across a broad spectrum of critical infrastructure sectors, including healthcare, education, legal, insurance, manufacturing, and technology.

First identified in June 2021 as a closed operation, Medusa evolved into a commercial Ransomware‑as‑a‑Service (RaaS) model in 2023. By leasing its payloads to a network of affiliates, the group has amplified its reach and increased the scale of its attacks. The current threat model is a dual‑extortion scheme that combines data exfiltration with full‑network encryption.

Key indicators of compromise (IOCs) have been extracted from public reporting. The primary payload, a Windows executable named gaze.exe, is responsible for terminating database services, deleting volume shadow copies, and encrypting files with an AES‑256 algorithm. Encrypted files receive the .medusa extension. Victims are typically given a 48‑hour window to negotiate via Tor‑based live chat or Tox messaging, with the threat actors threatening to auction stolen data if the deadline passes.

The attack chain follows a consistent pattern:

  • Initial Access – Credentials supplied by underground Initial Access Brokers (IABs), or exploitation of public software vulnerabilities such as CVE‑2024‑1709 (ScreenConnect), CVE‑2023‑48788 (Fortinet FortiClient EMS), CVE‑2026‑1731 (BeyondTrust), and older flaws in Fortra GoAnywhere MFT.
  • Privilege Escalation & Living‑Off‑The‑Land – Use of native Windows binaries like PowerShell, cmd.exe, and WMI to map internal networks while avoiding detection.
  • Defense Evasion – Deployment of stolen or custom kernel drivers to terminate Endpoint Detection and Response (EDR) solutions, dump credentials from LSASS memory, and abuse legitimate Remote Monitoring and Management (RMM) tools such as AnyDesk, Atera, and SimpleHelp.
  • Data Staging & Exfiltration – Utilization of tools like Mimikatz, CrackMapExec, and Rclone to harvest secrets and stage bulk exfiltration, often through encrypted tunnels or the dark‑web leak portal.
  • Payload Delivery & Encryption – Execution of gaze.exe, which stops security services, removes shadow copies, and encrypts the network.

Indicators of compromise are numerous and include a series of IP addresses, URLs, and domain names used for command and control, exfiltration, and remote sessions. The list is extensive and is intentionally defanged (e.g., using [.] instead of .) to prevent accidental resolution.

Impact assessment shows that over 500 organizations have been confirmed compromised, with average ransom demands near $260,000 and the possibility of payments reaching $15 million. The dual‑extortion strategy is designed to maximize revenue while forcing victims to pay quickly.

Mitigation recommendations for security analysts and operators are as follows:

  • Patch Management – Apply patches for the identified CVEs immediately, prioritizing those with public exploit code and those discovered within the last 24 hours.
  • Segmentation – Enforce strict network segmentation to limit lateral movement, especially between critical data stores and application servers.
  • Authentication Hardening – Deploy phishing‑resistant multifactor authentication and implement credential hygiene practices.
  • Backup Strategy – Maintain immutable, offline backups and verify restoration procedures regularly.
  • Endpoint Visibility – Audit endpoint telemetry for unauthorized RMM installations, anomalous execution of administrative tools, and unexpected kernel driver activity.
  • Threat Hunting – Track the specific IOCs listed in the report, monitor for the presence of gaze.exe, and watch for the .medusa file extension.
  • Incident Response – Prepare a coordinated response plan that includes isolation of infected systems, removal of malicious binaries, and secure data exfiltration handling.

By following these steps, organizations can reduce the likelihood of a successful Medusa attack, defend against data exfiltration and encryption, and protect critical infrastructure services from prolonged downtime.

Leave a Reply

Looking for the Best Cyber Security?

Seamlessly integrate local and cloud resources with our comprehensive cybersecurity services. Protect user traffic at endpoints using advanced security solutions like threat hunting and endpoint protection. Build a scalable network infrastructure with continuous monitoring, incident response, and compliance assessments.

Contact Us

Copyright © 2025 ESSGroup

Discover more from ESSGroup

Subscribe now to keep reading and get access to the full archive.

Continue reading