The Medusa crime gang has evolved into a ransomware-as-a-service Hydra, FBI warns
The monster has now grown many heads and sits at the center of a fast-growing criminal ecosystem.
Medusa started out as a tightly knit group of criminals wielding its own self-designed malware variants.
Now, the monster has grown many more heads, evolving into a massive ransomware-as-a-service ecosystem of affiliates, developers, and initial access brokers selling backdoors into compromised systems.
And like the mythical Hydra, cutting off one head does not necessarily kill the beast.
According to a joint advisory from the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the FBI, and the Department of Health and Human Services, Medusa has turned its gaze to more than 500 victims across critical sectors, including healthcare, education, manufacturing, technology, and government services.
Going from gang to ecosystem
The ransomware operation was first identified in 2021. Initially, Medusa operated as a closed group, with the same actors controlling development and attacks.
But since about 2023, it has operated under a RaaS model, allowing affiliates to use its tools in exchange for a share of ransom payments.
That year, threat intelligence analysts Anthony Galiette and Doel Santos of Palo Alto Networks' Unit 42 warned that it was "turning files into stone" and leaking stolen data onto Telegram channels.
Today, Medusa RaaS uses a double and even triple-extortion model.

READ MORE: The EU has “kill switches” in its critical systems. Can digital sovereignty fix them?
Victims are told they must pay to decrypt files and prevent further release of their data.
FBI investigators also found that after paying the ransom, one victim was contacted by a Medusa actor who claimed the negotiator had already stolen the ransom and requested that half of the payment be made again to provide the “true decryptor” - potentially indicating a triple-extortion scheme.
Countdown to exposure
The pressure does not stop with encryption. Medusa has built an extortion apparatus designed to keep victims under pressure while negotiations continue.
If the victim does not respond to the ransom note, Medusa actors contact them directly by phone or email. Additionally, Medusa operates a .onion data leak site that divulges victims' data, includes countdowns to the release of information, and even claims viewing figures to intimidate the target.
Victims that are still actively negotiating sometimes appear on the ransom site, and criminals use the threat of being added to this page as a tactic during talks.
Medusa actors also offer a “lower rate” for quick payments, stating that the discount will expire after an arbitrary period. They closely research victim financial details and base their demands on publicly posted revenue.
After a victim pays the ransom, the data is far from guaranteed to be safe.
"There is no way to verify that Medusa actors remove victim data from the site," CISA wrote.
Medusa advertises the sale of data and displays a countdown timer across its comms channels. Victims can pay $10,000 USD in cryptocurrency to extend the countdown timer by one day.
Cascading risk
The danger becomes more serious when the same techniques are used against critical infrastructure. An intrusion that begins in an ordinary IT system can potentially move into operational environments, where the consequences are no longer confined to stolen data, encrypted computers, or financial losses.
Joshua Penny, Senior Cyber Threat Intelligence Analyst at Bridewell, said that Medusa’s targeting of critical national infrastructure should be "taken seriously" because the consequences of attacks can unpredictably cascade through complex interconnected systems and domains.
However, there is no indication of "novel capabilities" or a "strategic intent to disrupt national infrastructure".
Penny said: "Medusa remains a financially motivated ransomware-as-a-service operation whose affiliates appear willing to exploit vulnerable organizations across a broad range of sectors. Its success continues to rely heavily on exposed internet-facing systems, inconsistent patching, compromised credentials and insufficiently controlled remote access.
"For critical infrastructure operators, the issue is therefore not that Medusa has developed an entirely new playbook, but that established ransomware techniques can produce disproportionately serious consequences."
New tricks with old weapons
That distinction is important. Medusa does not need a radically new weapon to cause serious damage. Its existing approach is potentially dangerous because critical infrastructure increasingly depends on interconnected IT and operational technology.
Medusa's modus operandi is to gain privileged access and then move laterally to find valuable systems to deploy ransomware. IT systems, internet connectivity, and transient devices remain major attack surfaces for ICS/OT infrastructure, and Medusa ransomware looks to exploit these.
READ MORE: Anthropic agents launch "turf wars", get stuck in "conflict loops" and kill each other's processes
James Neilson, SVP of Global at OPSWAT, said: "One of the major factors in why Medusa ransomware has been so successful in breaching critical infrastructure organizations is that there’s a lack of understanding among security teams regarding the impact of IT threats on OT environments.
"IT security controls are often directly applied to OT systems, which creates a false sense of security and causes disruptive false positives. Many organizations neglect to secure data that moves in and out of their OT networks and to implement security practices tailored to ICS/OT systems.
"CISA particularly advises segmenting networks to block lateral movement, and an effective way to do this is by controlling data flows and scanning files in transit. Organizations can then detect and neutralize hidden malicious payloads that may infiltrate their critical systems."
Why healthcare is particularly exposed
Few environments demonstrate the problem more clearly than healthcare. Hospitals combine conventional IT with medical devices, legacy technology and clinical systems that must remain available, creating numerous paths through which an intrusion can potentially spread.
Andrew Lintell, General Manager, EMEA at Claroty, said: “Healthcare’s prominence in this advisory is no coincidence. Hospitals rely on a complex mix of medical devices, legacy technology, and IT systems, meaning an initial compromise can spread beyond IT and disrupt the systems that support patient care. Medusa’s affiliate model only increases that risk by creating a market for access to these environments.
"The challenge is that many healthcare environments already possess devices that could provide attackers with an opportunity to gain or expand that access. Our own research found that 89% of healthcare organizations have IoMT devices that combine known exploitable vulnerabilities (KEVs) linked to active ransomware campaigns with insecure internet connections.
"Against this backdrop, visibility is not enough. Healthcare organizations need to use that insight to identify and prioritize their highest risk devices, reduce unnecessary internet exposure, and apply clinically aware segmentation to limit an attacker’s ability to move laterally towards critical systems. Crucially, those controls must reflect how devices are actually used in clinical workflows so organizations can contain an attack without introducing further disruption to patient care.”
Infrastructure vulnerability
The same underlying problem extends beyond healthcare. Critical infrastructure can present attackers with a combination of vulnerable entry points and unusually severe consequences once access has been gained.
Jon Abbott, CEO and Co-founder at ThreatAware, said: "The fact that around 200 organizations have been attacked in the past year proves that we're seeing critical infrastructure become an increasingly preferred target for threat actors.
"Medusa ransomware is well known for seeking out weaker points of entry into organizations to then move laterally to launch their attack on target systems. When considering the possibilities for disruption that an attack can cause, it's no surprise that these critical sectors are being targeted."