Most ransomware groups behave like messy extortionists, but Medusa runs like a lean supply chain.
In mid-August, federal agencies updated their Medusa advisory to reflect a grim milestone: over 500 confirmed victims across healthcare, manufacturing, and tech. The victim count jumped from 300 early last year because Medusa stopped doing everything in-house. Instead, they outsource initial network access to independent brokers, paying bounties up to $1 million for high-value targets, while affiliates handle the actual breaches using a shared ransomware-as-a-service model.
Medusa itself has been around since 2021. What has changed is how efficiently they divide the work. Since 2023, the operation has used a ransomware-as-a-service model, with affiliates receiving different levels of trust according to their experience and profitability. Newer operators may even leave ransom negotiation to Medusa’s developers. Initial access can simply be bought. The FBI says Medusa has offered brokers anywhere from $100 to $1 million, including incentives for exclusive access.
Tracking from Microsoft shows Medusa-linked actors weaponizing software flaws within 24 hours of public disclosure, and in some cases, exploiting zero-day vulnerabilities a week before a patch even exists. Storm-1175, exploited more than 16 vulnerabilities since 2023 across products including ConnectWise ScreenConnect, Ivanti, JetBrains TeamCity, GoAnywhere, SAP NetWeaver and BeyondTrust (Microsoft, 2026).. In one case, an SAP NetWeaver flaw disclosed on April 24, 2025, was being exploited the following day. Microsoft has also seen the group use zero-day exploits up to a week before public disclosure.
Once inside, attackers move from initial access to full data exfiltration in less than a day. They bypass security tools by living off the land, using legitimate remote-management software like AnyDesk, Atera, and PowerShell to move laterally across enterprise networks undetected.
For defenders, this creates an awkward collision with ordinary enterprise IT. A critical patch still has to be tested, approved and deployed without breaking a production system. Attackers have none of that process.
Medusa’s post-compromise toolkit is another headache because much of it has perfectly legitimate uses.
Even Interactsh, an open-source project built to help security researchers detect out-of-band vulnerabilities, appears in Medusa activity. The advisory says attackers have used its oast domains to check whether exploitation succeeded. Interactsh’s own GitHub repository describes it as a security-testing tool for detecting external interactions (GitHub, 2026).
Blocking obviously malicious binaries catches only part of the operation when attackers increasingly borrow the same remote access, deployment and diagnostic tools administrators use every day.