Medusa ransomware has now affected more than 500 organizations since it was first identified in June 2021, according to an updated joint advisory from the FBI, the Cybersecurity and Infrastructure Security Agency, and the U.S. Department of Health and Human Services.

Released on August 18, 2026, the update incorporates information from FBI investigations conducted as recently as April 2026. The victim list crosses multiple critical-infrastructure sectors, including healthcare, defense, critical manufacturing, government services, information technology, and financial services. Organizations in education, law, insurance, technology, and other industries have also been affected.

The number is important, but the structure behind it is more revealing. Medusa is no longer simply a ransomware developer deploying its own malware. It has become an access-driven criminal ecosystem in which affiliates, initial access brokers, stolen credentials, exposed services, legitimate administration tools, and a final ransomware payload are assembled into a repeatable intrusion process.

That model makes Medusa difficult to address with any single security control. It also makes the earliest stages of the attack—especially phishing and malicious-file delivery—valuable opportunities to break the chain before attackers acquire a working foothold.

From a closed operation to a ransomware marketplace

Medusa originally operated as a closed ransomware group, with the same organization controlling development and deployment. Since at least early 2023, however, it has evolved into a ransomware-as-a-service operation. Affiliates receive access to the platform according to their experience, reputation, and profitability, while core developers retain varying degrees of control over campaigns and ransom negotiations.

Medusa also buys access from initial access brokers. According to the government advisory, offers advertised on cybercriminal forums have ranged from approximately $100 to $1 million, depending on the organization, privilege level, persistence, and value of the compromised environment.

These brokers are generally not loyal to one ransomware brand. The same compromised credentials or remote foothold may be offered to Medusa, another ransomware operation, or multiple buyers. This creates an important distinction: a user who falls for a credential-phishing message may not see ransomware immediately. The stolen account can be validated, enriched with information about the victim, resold, and weaponized days or weeks later.

The phishing message and the eventual appearance of gaze.exe, Medusa’s reported encryption component, may therefore be separated by several intermediaries and multiple stages of attacker activity.

How phishing feeds the Medusa ecosystem

The updated advisory identifies phishing campaigns, particularly phishing intended to steal credentials, as one of Medusa’s initial-access methods. It does not describe a single universal “Medusa phishing attachment,” and defenders should not expect every campaign to use the same document, archive, script, sender profile, or delivery infrastructure.

Instead, phishing can feed Medusa operations through several paths.

Credential-harvesting messages

An email may impersonate a familiar organization, administrator, cloud service, document-sharing platform, benefits provider, or security notification. The victim is directed to a counterfeit sign-in page where credentials are collected.

If the stolen account is not protected by phishing-resistant multi-factor authentication, attackers may use it to access email, VPN, remote desktop services, cloud applications, or internal systems. An initial access broker can then package and sell that access to a Medusa affiliate.

In this path, the email itself may contain nothing more than a link. There may be no malicious attachment for a file-security product to disarm.

Files that conceal or redirect the phishing step

Other campaigns use attachments to make the lure appear more legitimate or to move the malicious destination outside the visible email body. Examples across the wider phishing ecosystem include:

  • PDF or Office documents containing deceptive buttons and external links.
  • HTML attachments that render a locally hosted credential-harvesting form.
  • Archives containing scripts, shortcut files, disk images, or executable content.
  • Documents with macros, embedded objects, remote templates, or exploit-triggering structures.
  • Files that display a decoy while launching or retrieving a second-stage payload.

The attachment may not contain Medusa ransomware itself. Its purpose may be to steal credentials, start a downloader, install remote-access software, or establish the foothold that is later sold to an affiliate.

This distinction matters. Ransomware rarely needs to arrive in its final form inside the original email. The first file only needs to create one reliable transition from a user-controlled environment to an attacker-controlled one.

Trusted-account phishing

Once attackers compromise an email account, they can send convincing messages from a real organization, continue existing conversations, or distribute malicious files through trusted file-sharing services.

This increases the chance that downstream recipients will open the content. It also means sender reputation alone is not enough: a trusted account can deliver an untrusted file.

Post-compromise delivery

Phishing can also provide credentials rather than code. After signing in through VPN, RDP, webmail, or another remote service, the attacker can upload scripts, remote-management agents, credential-dumping tools, and eventually the ransomware payload.

By that stage, email filtering has already been bypassed. File inspection must extend beyond the inbox to web uploads, collaboration platforms, managed file-transfer systems, network shares, remote sessions, and other file-ingress points.

The other major entry path: exposed and unpatched systems

Phishing is only part of the Medusa story. The operation also targets internet-facing systems with known vulnerabilities. The updated advisory and related Microsoft research associate Medusa activity with flaws affecting products such as ConnectWise ScreenConnect, Fortinet FortiClient EMS, Fortra GoAnywhere MFT, SimpleHelp, BeyondTrust, Microsoft Exchange, PaperCut, Ivanti appliances, CrushFTP, JetBrains TeamCity, SmarterMail, and SAP NetWeaver.

Microsoft describes the Medusa-associated actor it tracks as Storm-1175 as a high-tempo operator. In some cases, it has moved from initial exploitation to data theft and ransomware deployment within 24 hours. The actor primarily weaponizes recently disclosed vulnerabilities, sometimes within a day of disclosure.

Microsoft has also observed Storm-1175 exploiting several vulnerabilities before public disclosure. That indicates either advanced exploit access, acquisition through brokers, or independent research, but it does not by itself establish that Medusa’s core developers created those zero-day exploits.

The practical lesson is that defenders cannot treat patching as a monthly administrative exercise. For exposed systems, the useful response window may now be measured in hours.

What happens after initial access

Whether the entry point is stolen credentials, a purchased foothold, a weaponized file, or an exploited server, Medusa affiliates tend to rely heavily on legitimate tools and living-off-the-land techniques.

A representative intrusion may progress through the following stages:

  1. Initial foothold: Phishing, stolen credentials, an initial access broker, exposed remote services, or exploitation of an internet-facing application.
  2. Persistence: Creation of new accounts, installation or takeover of remote-management software, deployment of web shells, or modification of existing remote-access infrastructure.
  3. Credential access: Collection of credentials with tools such as Mimikatz, LSASS dumping, cached credential extraction, or theft of Active Directory data.
  4. Discovery: Enumeration of users, systems, domains, network shares, security products, backup infrastructure, and high-value data.
  5. Lateral movement: Use of RDP, PsExec, PowerShell, SMB, Group Policy, PDQ Deploy, BigFix, SimpleHelp, AnyDesk, ScreenConnect, or other administration tools.
  6. Data collection and exfiltration: Staging and removal of sensitive information using utilities such as Rclone, Robocopy, remote-management channels, proxies, or attacker-controlled servers.
  7. Defense disruption: Termination of security processes, deletion of shadow copies, interference with backup services, and, in some reported activity, use of vulnerable drivers to disable endpoint protection.
  8. Encryption: Distribution and execution of the Medusa encryptor, reported as gaze.exe, followed by encryption of accessible data and addition of the .medusa extension.

Microsoft has observed Storm-1175 using PDQ Deploy to distribute a command script and the Medusa payload across compromised environments. In other cases, attackers with sufficient privileges have used Group Policy to deploy ransomware broadly.

This is why the first compromised account or workstation matters so much. It is not the end of the attack; it becomes a distribution point for everything that follows.

The extortion clock

Medusa uses a double-extortion model: attackers steal data before encrypting systems and threaten to publish the stolen information if the victim refuses to pay.

Victims are generally instructed to make contact within 48 hours. If they do not respond, Medusa operators may contact the organization directly by email or telephone. Victim information is placed on the group’s leak site with a public countdown, and stolen data may be advertised to third parties before the timer expires.

Medusa has also offered victims the option to pay approximately $10,000 in cryptocurrency to add one day to the countdown. Other charges may be presented for deleting the stolen information or allowing it to be downloaded.

The FBI, CISA, and HHS discourage ransom payments. Payment does not guarantee recovery, deletion of stolen data, or protection against subsequent extortion. At least one reported Medusa victim was approached with an additional demand after making an earlier payment.

Where FileDNA CADR can break the chain

FileDNA Content Analysis, Disarm and Reconstruction is designed to operate as part of a broader Content Security Layer, or CSL. Its role is specific: examine untrusted files before they are opened, parsed, imported, or executed downstream.

FileDNA breaks an incoming file into its structural components, including embedded objects, scripts, macros, metadata, links, encoded material, and nested content. Policy can then remove or neutralize unsafe active elements, after which the permitted content is reconstructed into a usable file.

In a file-borne phishing path, that creates several opportunities for prevention.

Weaponized Office documents and PDFs

If a phishing attachment contains macros, embedded scripts, executable objects, malformed structures, remote-content references, or other prohibited active components, FileDNA CADR can analyze those elements before the document reaches the user. The reconstructed version retains permitted business content while removing or neutralizing the components that enable the attack.

The result is not merely a warning that the file appears suspicious. The objective is to deliver a version in which the unwanted execution path is no longer present.

HTML and script-based attachments

HTML attachments and standalone scripting files can serve as local phishing pages, redirectors, downloaders, or execution stages. A content-security policy can inspect their code and capabilities, block the file, or produce a safe representation when reconstruction is appropriate.

This can prevent an attachment from turning a trusted email application into the launch point for credential theft or payload retrieval.

Nested archives and concealed content

Attackers frequently use archives and multiple embedding layers to hide a script, executable, shortcut, or second document from superficial inspection. Deep structural analysis allows the outer container and its internal objects to be evaluated as a connected content hierarchy rather than as unrelated files.

That is especially important when the visible attachment is harmless but an object several layers below it carries the active component.

Files delivered after the initial compromise

CADR is most effective when deployed at more than the email gateway. A Content Security Layer can inspect files entering through web downloads, file-sharing services, collaboration systems, managed transfer platforms, uploads, network boundaries, and AI ingestion pipelines.

This matters in a Medusa-style intrusion because later tools, including remote-access agents, scripts, command files, credential utilities, and the ransomware binary, may be transferred after attackers already possess valid credentials.

If those artifacts cross a FileDNA-controlled inspection point, policy can block them, quarantine them, or prevent unsafe content from reaching its destination. Whether executable binaries are blocked or analyzed, rather than reconstructed, should be defined by deployment policy and the capabilities enabled for that file type.

Where FileDNA does not break the chain

FileDNA CADR should not be positioned as a complete Medusa defense. Its value is strongest when an attack depends on a file crossing a controlled content boundary.

It does not independently prevent:

  • A user from entering credentials into a phishing page reached through a plain email link.
  • Authentication with credentials that were already stolen.
  • Session-cookie theft or adversary-in-the-middle phishing when no inspectable file is involved.
  • Direct exploitation of ScreenConnect, GoAnywhere, Fortinet EMS, BeyondTrust, or another exposed service.
  • Abuse of an already authorized RMM platform when no new file passes through the CADR inspection path.
  • Living-off-the-land commands typed through an existing remote session.
  • Lateral movement, credential dumping, data exfiltration, or encryption after an attacker has obtained sufficient control.

Those stages require complementary controls: phishing-resistant MFA, rapid patching, identity monitoring, least privilege, application control, endpoint detection and response, network segmentation, RMM governance, egress monitoring, immutable backups, and tested incident-response procedures.

The correct architecture is therefore not CADR instead of EDR, email security, identity protection, or vulnerability management. It is CADR before execution, combined with those controls around and after execution.

A practical defense model

Organizations concerned about Medusa should prioritize several actions together:

  • Patch known exploited vulnerabilities on internet-facing systems according to exposure and active-exploitation risk—not only according to a routine calendar.
  • Require phishing-resistant MFA for email, VPN, administrative access, and critical applications.
  • Route inbound and transferred files through a Content Security Layer before users, applications, or automated systems consume them.
  • Restrict remote-management tools to approved products, administrators, destinations, and time periods.
  • Monitor the creation of accounts, changes to Group Policy, deployment through PDQ or similar tools, suspicious PowerShell use, and unexpected RDP or SMB activity.
  • Segment workstations, servers, backup systems, and administrative networks to limit lateral movement.
  • Control outbound transfers and monitor tools such as Rclone, Robocopy, remote-access software, and proxy services.
  • Maintain offline or immutable backups and regularly test restoration procedures.
  • Report ransomware incidents to CISA or the FBI even if a payment has not been made.

The larger lesson

Medusa’s growth beyond 500 victims is not simply evidence of a successful ransomware binary. It demonstrates the efficiency of an ecosystem that separates credential theft, vulnerability exploitation, access brokerage, lateral movement, data theft, encryption, and extortion into reusable criminal services.

Phishing remains valuable to that ecosystem because attackers do not need every message to deliver ransomware. A stolen credential, opened document, executed script, or installed remote-management agent can be enough to create access that will later be sold or converted into a ransomware incident.

FileDNA CADR can remove one of the attacker’s most dependable advantages: the ability to place active, concealed, or structurally unsafe content inside files that users and business systems are expected to trust. As part of a Content Security Layer, it moves prevention upstream before an attachment becomes code and before a file becomes the first compromised endpoint.

It does not close every Medusa entry path. No credible security layer does. But wherever the attack requires a weaponized file to cross a controlled boundary, CADR provides a concrete opportunity to stop the chain before the ransomware operation has a network to extort.

References