CyberzSOC

Publication detail
← Back to advisories & guidance

CISA and Partners Release Cybersecurity Advisory on Medusa Ransomware ↗ source

March 12, 2025 CISA Alert
Co-sealed by: CISA, FBI, MS-ISAC

Summary

This advisory provides tactics, techniques, and procedures (TTPs), indicators of compromise (IOCs), and detection methods associated with known Medusa ransomware activity. Medusa is a ransomware-as-a-service variant used to conduct ransomware attacks; as of December 2024, over 300 victims from critical infrastructure sectors have been impacted. Medusa actors use common techniques like phishing campaigns and exploiting unpatched software vulnerabilities. Immediate actions organizations can take to mitigate Medusa ransomware activity: Filter network traffic by preventing unknown or untrusted origins from accessing remote services. This product is provided subject to this Notification and this Privacy & Use policy.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

No CVEs are referenced in this publication.

Vendors Named in This Publication

No KEV-catalogued vendors are named in this publication.