Medusa Ransomware

    Date: 08/21/2026

    Severity: Critical

    Summary

    Medusa is a Ransomware-as-a-Service (RaaS) operation first identified in 2021 that uses double extortion, encrypting victim data while threatening to leak stolen information. As of April 2026, Medusa actors had impacted more than 500 victims across critical sectors including healthcare, education, legal, insurance, technology, and manufacturing. The updated FBI/CISA/HHS advisory highlights its affiliate model, exploitation of vulnerabilities, initial access brokers, PowerShell obfuscation, network reconnaissance, persistence, and C2 tooling, demonstrating an active and evolving ransomware threat. 

    Indicators of Compromise (IOC) List

    Domains/Urls

    http//45.61.150.94:8000/storm.exe

    https://3324.requestcatcher.com/hihi

    IP Address

    143.244.47.89

    167.88.166.173

    143.110.243.154

    erp.ranasons.com

    185.238.231.16

    23.234.89.195

    146.70.172.247

    155.2.215.71

    23.234.106.242

    23.234.93.112

    37.19.21.180

    155.2.215.69

    185.238.231.98

    37.221.66.239

    185.135.86.185

    83.138.53.139

    185.238.231.4

    185.238.231.77

    185.238.231.85

    85.155.186.121

    94.156.67.145

    Hash

    2C7F328FEEB94608AAAF99EC70CB0323

    D796259C44BE852327623FD2E40C47F2

    4D0B6E3C9C33550A005E41663A1977CB

    eb05429d25fc57b476428cdb0a134b2f

    04b13b6cd5e5291b1cde78975a140feea

    7fd3bc3777c53caa1ab33426c83bfcc

    b29defbbc4ebaa243c1712ccc4943374f

    1b6fb864c39ed9f70fceb17eee098db

    44370f5c977e415981febf7dbb87a85c

    8f11d9067da087cb4185fa804caac2df

    2df705c9be0465f1c73a9f5d35147723deb

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    domainname like "https://3324.requestcatcher.com/hihi" or url like "https://3324.requestcatcher.com/hihi" or siteurl like "https://3324.requestcatcher.com/hihi" or domainname like "erp.ranasons.com" or url like "erp.ranasons.com" or siteurl like "erp.ranasons.com" or domainname like "http//45.61.150.94:8000/storm.exe" or siteurl like "http//45.61.150.94:8000/storm.exe" or url like "http//45.61.150.94:8000/storm.exe"

    Detection Query 2 :

    dstipaddress IN ("143.244.47.89","155.2.215.69","146.70.172.247","37.19.21.180","143.110.243.154","185.238.231.4","185.238.231.16","23.234.89.195","185.238.231.98","23.234.93.112","83.138.53.139","37.221.66.239","94.156.67.145","185.238.231.85","185.238.231.77","23.234.106.242","185.135.86.185","167.88.166.173","155.2.215.71","85.155.186.121") or srcipaddress IN ("143.244.47.89","155.2.215.69","146.70.172.247","37.19.21.180","143.110.243.154","185.238.231.4","185.238.231.16","23.234.89.195","185.238.231.98","23.234.93.112","83.138.53.139","37.221.66.239","94.156.67.145","185.238.231.85","185.238.231.77","23.234.106.242","185.135.86.185","167.88.166.173","155.2.215.71","85.155.186.121")

    Detection Query 3 :

    md5hash IN ("4D0B6E3C9C33550A005E41663A1977CB","eb05429d25fc57b476428cdb0a134b2f","44370f5c977e415981febf7dbb87a85c","2C7F328FEEB94608AAAF99EC70CB0323","D796259C44BE852327623FD2E40C47F2","04b13b6cd5e5291b1cde78975a140feea","7fd3bc3777c53caa1ab33426c83bfcc","b29defbbc4ebaa243c1712ccc4943374f","1b6fb864c39ed9f70fceb17eee098db","8f11d9067da087cb4185fa804caac2df","2df705c9be0465f1c73a9f5d35147723deb")

    Reference:    

    https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-071a                                   


    Tags

    CVE-2025CVE-2026ObfuscationMalwareThreat ActorVulnerabilityCISAMedusaRaaSRansomwareExtortionHealthcare and Public HealthEducationGovernment Services and FacilitiesFinancial ServicesInformation TechnologyCritical ManufacturingExploitCVE - 2024CVE-2023

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags