Medusa Ransomware: Triple Extortion and Exploding Infections
2025-03-16

A joint advisory from the FBI, CISA, and MS-ISAC warns of the escalating threat of Medusa ransomware, a RaaS operation exploiting vulnerabilities like CVE-2024-1709 and CVE-2023-48788, and phishing campaigns. Medusa employs a double extortion tactic, now evolving into a 'triple extortion' scheme where attackers demand further payments after receiving the initial ransom. Victims span critical infrastructure sectors, including healthcare, education, and legal, with at least 300 infections in the first two months of 2025. The advisory recommends multi-factor authentication, prompt patching, and other security measures to mitigate the risk.
Tech