
The Actor: Who Is Medusa?
On August 18, 2026, CISA, the FBI, and the U.S. Department of Health and Human Services updated their joint Cybersecurity Advisory on Medusa ransomware. As of April 2026, Medusa developers and affiliates had impacted more than 500 victims across critical infrastructure sectors, up from more than 300 reported as of February 2025. Affected industries include medical, education, legal, insurance, technology, and manufacturing.
First identified in June 2021, Medusa has evolved into a ransomware-as-a-service (RaaS) operation supported by affiliates and initial access brokers. Medusa uses double extortion, encrypting victim systems while threatening to publish stolen data if payment is not made. It should not be confused with MedusaLocker or Medusa mobile malware, which are separate threats.
Initial access:Â Rapid Exploitation Increases the Risk
Exploiting Vulnerabilities Before Defenders Can Respond:
Medusa actors opportunistically target organizations running vulnerable internet-facing systems and services.
Rather than relying on a single method of entry, affiliates exploit known vulnerabilities and can also obtain access through initial access brokers. This approach allows Medusa to capitalize on exposed infrastructure and unpatched systems while reducing the time defenders have to identify and contain an intrusion.
Evolving TTPs: What Makes Medusa Dangerous
Gunra actors primarily gain access by exploiting vulnerabilities in internet-facing firewall and VPN appliances. The joint advisory highlights CVE-2024-55591 and CVE-2025-24472, authentication bypass flaws affecting certain FortiOS and FortiProxy versions.
Once inside, attackers have used Impacket tools including psexec.py and smbclient.py for lateral movement over SMB. Investigators also documented abuse of default VPN administrator credentials, SSH tunneling for persistence, stolen session information, and RDP access to critical systems.
Before encryption, Gunra actors have used WMI to delete Windows volume shadow copies and have deleted backup and archived data from backup infrastructure, limiting recovery options. The combination of compromised credentials, legitimate administrative utilities, cloud services, and cross-platform ransomware makes Gunra difficult for traditional signature-based defenses to contain.
The BlackFog Perspective: BlackFog’s Real-Time Defense For Risk Mitigation
Stops data theft before encryption
Medusa relies on stolen information as leverage during extortion. BlackFog’s anti data exfiltration (ADX) technology helps prevent unauthorized outbound data transfers before attackers can use sensitive information against the organization.
Detects abuse of legitimate applications
Medusa regularly uses legitimate remote administration and system management tools to blend into normal enterprise activity. Behavioral analysis helps identify suspicious use of trusted applications rather than relying solely on known malware signatures.
Responds to evolving attack techniques
Medusa’s exploitation of vulnerable internet-facing infrastructure means organizations cannot rely exclusively on traditional signature-based detection. BlackFog’s behavioral approach focuses on abnormal activity and data movement as attacks evolve.
Limits the impact of compromised credentials
Credential theft and remote access play an important role in Medusa intrusions. Behavioral monitoring helps identify unusual activity associated with compromised accounts and devices before attackers can extend their reach across the network.
