Back Technadu Medusa Ransomware Tops 500 Victims as STORM-1175 Exploits Flaws Fast
Medusa developers and affiliates have surpassed 500 victims as of April 2026, marking a substantial increase from the more than 300 critical-infrastructure organizations cited in the agencies' original March 2025 advisory. Also, new research from Microsoft Threat Intelligence details how quickly Medusa-related operators can turn newly disclosed vulnerabilities into ransomware attacks.
An updated joint advisory from the Cybersecurity and Infrastructure Security Agency (CISA) and the FBI adds HHS as a co-sealer and highlights more specifics on the affiliate model and payment ranges for initial access brokers, a broader list of exploited vulnerabilities, use of Interactsh URLs to verify exploits, additional tools for network enumeration, persistence, and stealth, and an increasingly serious focus on healthcare.
The CISA and FBI advisory describes Medusa as operating through an affiliate model, with affiliates gaining access to the ransomware operation's tools and infrastructure. The agencies have also documented the use of legitimate remote-management software during intrusions.
Medusa has not added new victims to its leak site since April, according to the updated information. The new tools and tactics observed in the advisory include:
STORM-1175, a financially motivated actor associated with Medusa ransomware operations, has exploited more than 16 vulnerabilities since 2023, frequently moving from initial access to data theft and ransomware deployment within days and, in some cases, within 24 hours .
The group primarily exploits N-days, but Microsoft has also observed STORM-1175 using zero-days, including flaws exploited up to a week before public disclosure.
The research cites recent activity involving products including Fortra GoAnywhere vulnerability CVE-2025-10035 ( CWE-502 : Deserialization of Untrusted Data) and BeyondTrust vulnerability CVE-2026-1731 ( CWE-78 : OS Command Injection).
The advisory stresses that Medusa actors operate opportunistically by targeting unpatched software rather than specific organizations or sectors. Yet, “ the Healthcare and Public Health (HPH) Sector has been a frequent victim of Medusa operations ,” according to the advisory.
Organizations should:
Microsoft's research also recommends maintaining visibility over externally exposed systems because the window between vulnerability disclosure and exploitation can be extremely short.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
