• News/
  • https://www.theregister.com/2025/03/13/medusa_ransomware_infects_300_critical/

Medusa ransomware infects 300+, uses 'triple extortion'

The Register
·
Jessica Lyons
·
Published Mar 13, 2025
·
Updated

A crook who distributes the Medusa ransomware tried to make a victim cough up three payments instead of the usual two, according to a government advisory on how to defend against the malware and the gangs who wield it. The joint report issued on Wednesday by the FBI, CISA, and the Multi-State Information Sharing and Analysis Center (MS-ISAC) reminds us that Medusa is a globe-spanning ransomware-as-a-service (RaaS) operation that recruits third-party affiliates to plant ransomware and negotiate with victims once it’s encrypted data. Uncle Sam’s infosec agencies prefer to call those affiliates “Medusa actors.” They’re also sometimes labeled “initial access brokers” (IABs) because part of their job is to crack victims’ IT defenses so that systems can be infected. Whatever you call these third-party entities, they often attack with credential-stealing phishing campaigns or by exploiting unpatched software bugs. Among their favorite flaws to target are CVE-2024-1709, a critical ConnectWise ScreenConnect authentication bypass bug, and the Fortinet EMS SQL injection vulnerability CVE-2023-48788. Once Medusa miscreants get their ransomware running, they use a double extortion strategy that sees them demand payments to decrypt the scrambled data and to prevent its release. Even orgs that have good ransomware recovery regimes, meaning they don’t need to unscramble encrypted data as they have good backups and fall-back plans, may consider paying to prevent the release of their stolen da...

Read full article

Affected Software

3 affected components
ConnectWise ScreenConnect
Fortinet EMS
ConnectWise Connectwise
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main threat discussed in this article?

The article discusses the Medusa ransomware and its use of 'triple extortion' tactics.

2

How many victims has the Medusa ransomware reportedly infected?

The Medusa ransomware has infected over 300 victims.

3

What is 'triple extortion' in the context of ransomware attacks?

'Triple extortion' refers to the tactic of demanding payments from multiple sources beyond the primary victim, such as clients or suppliers.

4

What types of software are specifically mentioned as being affected by Medusa ransomware?

The affected software includes ConnectWise ScreenConnect, Fortinet EMS, and ConnectWise's own product.

5

What kind of guidance has been provided to defend against the Medusa ransomware?

A government advisory has been issued to help organizations defend against Medusa ransomware attacks and affiliated criminal gangs.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203