In partnership with the Federal Bureau of Investigation (FBI) and Multi-State Information Sharing and Analysis Center (MS-ISAC)—we released a joint Cybersecurity Advisory, #StopRansomware: Medusa Ransomware https://go.dhs.gov/wcW.
This advisory provides network defenders with indicators of compromise (IOCs), tactics, techniques, and procedures (TTPs), and detection methods associated with Medusa ransomware activity identified through FBI investigations.
Medusa is a ransomware-as-a-service (RaaS) variant first identified in June 2021. As of December 2024, Medusa developers and affiliates have impacted over 300 victims from a variety of critical infrastructure sectors with affected industries including medical, education, legal, insurance, technology, and manufacturing.
Actions your organization can take include ensuring operating systems, software, and firmware are patched and up to date; segment networks to restrict lateral movement from initial infected devices and other devices; filter network traffic by preventing unknown or untrusted origins from accessing remote services on internal systems.
Organizations are encouraged to review the advisory and implement recommended mitigations to protect against the ransomware threat actor.