Medusa 2026: The Ransomware Stage Begins After Identity and Remote Management Are Lost

Medusa’s 2026 attack chain shows how exposed edge systems, OAST callbacks, identity theft, RMM abuse, and deployment tools can lead to ransomware at enterprise scale.

Govern What the Control Plane Executes
  • August 21, 2026

The latest Medusa federal advisory outlines an easily replicable chain of events leading from initial access through enterprise-wide control, exploit, verify access, remote access, credentials/policy, data exfiltration and finally distributing the encryptor via administrative infrastructure.

This advisory, updated on August 18, 2026 using FBI data up until April, states over 500 victims, not just for 2026. Medusa is different from MedusaLocker and Medusa mobile malware.

Encryption is the final visible act, not the first loss of control. The critical points are the edge, the identity systems and administrative tools.

The Edge Window Is Measured in Hours

The list identifies four initial access weaknesses as follows, ConnectWise ScreenConnect CVE-2024-1709, Fortinet FortiClient EMS CVE-2023-48788, Fortra GoAnywhere MFT CVE-2025-10035, and BeyondTrust Remote Support / Privileged Remote Access CVE-2026-1731.

Actors have the ability to turn the newly disclosed vulnerabilities into exploits within 24 hours and exploit them even before any disclosure. There is no evidence that Medusa creates zero-day vulnerabilities.

Storm-1175 exploits web-facing vulnerabilities quickly and uses Medusa ransomware. This is not the telemetry for all Medusa affiliates, but it shows the fast exposure-to-impact cycle.

In internet-facing management tools, remote access, and file transfer services, the most important thing is decreasing exposure time. Patching does not remove the web shell, the account,

OAST Callbacks Are an Early Detection Opportunity

According to the post, attackers made use of Interactsh URLs for validation of exploitation through oast[.]site, oast[.]pro, and oast[.]fun.

Interactsh is a legitimate OAST solution, and hence, it would not be accurate to say that the mere presence of the domain on your infrastructure is enough to confirm an intrusion.

Rather, tie an unexpected callback from an edge production asset to the previous request, app error, and next steps performed by the actor. The following actions after a callback: shell execution, powershell, account creation, RMM deployment, or tunnel creation should raise alarm bells.

By the Time You See .medusa, the Network Was Already Theirs

FROM EXPOSED EDGE SYSTEM TO ENTERPRISE EXECUTION

Medusa evolved into an affiliate model from at least early 2023. The advisory describes phishing, initial access brokers, and exploitation of public-facing software.

01 Exposed edge system
02 OAST callback
03 RMM or tunnel
04 Identity compromise
05 GPO or deployment control
06 Exfiltration
07 Ransomware deployment
Where Defenders Can Interrupt It
Edge exposure

Keep an authoritative internet-facing inventory, and patch or restrict exposed systems in hours, not weeks.

Callback confirmation

Correlate an OAST hit with the request that preceded it and the process that followed.

Identity theft

Once domain credential material is exposed, endpoint cleanup alone is not containment.

GPO or deployment

Watch the control plane, not only endpoints; a policy or deployment change fans out faster than manual movement.

THE FOUR NAMED EDGE VULNERABILITIES
Product CVE Weakness Class Added to KEV
ConnectWise ScreenConnect CVE-2024-1709 Auth bypass, alternate path Feb 22, 2024
Fortinet FortiClient EMS CVE-2023-48788 SQL injection Mar 25, 2024
Fortra GoAnywhere MFT CVE-2025-10035 Deserialization, command injection Sep 29, 2025
BeyondTrust RS / PRA CVE-2026-1731 Pre-auth command injection Feb 13, 2026

GoAnywhere MFT and BeyondTrust RS/PRA were added to the advisory in the 2026 update, extending the perimeter focus beyond remote-access and endpoint tools into managed file transfer and privileged-access appliances.

THE ZERO-DAY QUESTION
16+

Vulnerabilities Storm-1175 has exploited since 2023

1 day

Fastest observed weaponization of a disclosed flaw

3

Zero-days Microsoft observed Storm-1175 use, roughly a week before public disclosure

The federal advisory finds no evidence that Medusa develops its own zero-days. Microsoft’s narrower telemetry on Storm-1175 shows zero-day use regardless, including GoAnywhere MFT and SmarterMail CVE-2026-23760. The two findings describe different scopes, not a contradiction.

AFTER THE NOTE APPEARS
Response window 48 hours
Contact channel Tor chat or Tox
Countdown extension $10,000 per day
Reported anomaly Second actor demanded another half-payment

One victim who had already paid was approached by a second Medusa actor for a claimed “true decryptor.” The advisory treats this as either early triple extortion or simple operational dysfunction among affiliates, not as a confirmed standard model.

ACCESS INFRASTRUCTURE ABUSED
Initial access broker payment range $100 – $1,000,000
Remote-management and tunneling tools observed
AnyDesk Atera ConnectWise BeyondTrust SimpleHelp Splashtop Nezha MeshAgent Ligolo-ng Cloudflared GSocket
Built-in tools for movement and discovery
PsExec WMI RDP Advanced IP Scanner SoftPerfect Network Scanner NetExec / CrackMapExec

None of these tools are malware by default. The signal worth alerting on is a first-seen agent, an unapproved tunnel, or a shell spawned from one of them, not the product name itself.

© 2026 XCITIUM THREAT LABS

Remote-Management Tools Become Access Infrastructure

The advisory highlights the abuse of RMM tools and tunneling tools such as AnyDesk, Atera, ConnectWise, BeyondTrust, SimpleHelp, Splashtop, Nezha, MeshAgent, Ligolo-ng, Cloudflared, and GSocket. Additionally, the advisory mentions PsExec, WMI, and RDP for moving and executing.

These are legitimate technologies, not malicious software by default. Detect newly seen RMM tools/services/tenants, unauthorized tunnels, shell/PowerShell child processes, and remote access preceding credential theft, security modifications, or widespread usage.

Similarly, MITRE suggests a behavior chain for tool-agnostic remote access, which includes executing an agent, persistence, continuous outgoing communication, and child process interaction.

Identity Compromise Is the Pivot

The federal findings include Mimikatz, Task Manager and comsvcs.dll LSASS dumping, mimilib.dll registered as an LSA Security Package, and VSS theft of ntds.dit with SYSTEM and SECURITY hives.

The advisory says mimilib.dll logged plaintext credentials to C:\Windows\System32\kiwissp.log, creating persistent collection rather than a one-time dump. VSS theft of Active Directory material should trigger controlled identity recovery, not merely local cleanup.

High-priority telemetry includes rundll32.exe loading comsvcs.dll with MiniDump semantics, LSASS access, changes to the LSA Security Packages registry value, kiwissp.log, VSS creation, copies from HarddiskVolumeShadowCopy*, access to ntds.dit/SYSTEM/SECURITY, and subsequent archive or transfer activity.

GPO and Deployment Platforms Are Ransomware Fan-Out Controls

Medusa actors modified the Default Domain Policy to Enabled, Enforced, superseding any more restrictive policy. This guidance also refers to PsExec, PDQ Deploy, and BigFix; Microsoft also notes Group Policy deployment in Storm-1175 campaigns.

This federal guidance explains a PDQ playbook that excluded C, from Defender, copied gaze.exe into System32, verified it, and executed it. Hence, deployment tools and Group Policy should be managed like privileged execution facilities.

Warn on modified packages/playbooks, exclusion for Defender, unrecognized payloads, expanded scope of targets, new operators, and deletion of logs. In the case of GPO, look at Active Directory modifications, such as Event ID 5136 correlated with writes to SYSVOL, including ScheduledTasks.xml and GptTmpl.inf.

Defend Before the .medusa Extension

Bandizip and Rclone were used for staging and exfiltration, sometimes with renamed files; rdpclip.exe was also used for smaller transfers. Detect the behavioral sequence, concentrated reads from valuable shares, archive creation, cloud-transfer behavior, a new destination, and unusual remote-session context.

The impact stage includes service stops, shadow-copy deletion, AES-256 encryption, .medusa extensions, ransom notes, and possible virtual-machine encryption. The 2026 advisory describes a post-payment second demand but does not establish triple extortion as Medusa’s standard operating model.

When a relevant exposure or callback appears, scope new accounts, RMM services, tunnels, identity theft, GPO/deployment changes, egress, backup, and hypervisor access. If Active Directory material or deployment infrastructure was touched, preserve evidence and execute controlled recovery.

Ransomware response cannot begin at encryption. The earlier signals a callback, tunnel, abnormal RMM agent, LSASS or NTDS access, policy change, deployment edit, or archive-and-egress sequence are where the operation can be disrupted before it becomes the business event.

First 60 Minutes: Hunt the Control Plane

When a relevant edge exposure or OAST callback is identified, begin with a time-bounded control-plane hunt:

  • Determine whether ScreenConnect, FortiClient EMS, GoAnywhere MFT, BeyondTrust, or another management or transfer system was externally reachable during the relevant exposure window.
  • Preserve edge, WAF, reverse-proxy, DNS, proxy, firewall, NetFlow, EDR, PowerShell, RMM, Active Directory, SYSVOL, PDQ/BigFix, backup, and hypervisor logs before rebuilding or removing tools.
  • Hunt for new local/domain accounts, additions to Administrators, Domain Admins, Enterprise Admins, Remote Desktop Users, and Group Policy Creator Owners, then correlate those identities with RDP, PsExec, WMI, RMM, or deployment activity.
  • Search for comsvcs.dll, LSASS access, LSA Security Package changes, kiwissp.log, VSS-to-NTDS activity, encoded PowerShell, certutil downloads, Defender exclusions, and long-lived outbound tunnels.
  • Review Group Policy, SYSVOL, PDQ, BigFix, and other deployment systems for new packages, altered playbooks, encoded PowerShell, unknown payload hashes, broad target scope, unfamiliar operators, or deleted job history.
  • Identify archive-and-egress behavior, changed backup credentials, hypervisor administration, and access to recovery infrastructure.

If the actor reached Active Directory, privileged remote access, or enterprise deployment systems, the incident is no longer an endpoint-only event. Containment must include the identity, remote-management, deployment, backup, and virtualization planes, with evidence preservation and credential recovery sequenced to prevent surviving access from re-entering the environment.

Conclusion: Ransomware Begins Before the Encryptor Runs

The defining lesson from Medusa is that ransomware is not primarily an encryption event. Encryption is the final visible consequence of a control failure that may have started much earlier at an exposed edge system and progressed through remote access, identity compromise, and administrative infrastructure.

The attack paths described here show that progression clearly. Public-facing vulnerabilities can provide initial execution. RMM agents, tunnels, web shells, PowerShell, PsExec, WMI, and RDP can extend access. Credential dumping against LSASS and Active Directory can turn local compromise into identity control. Group Policy and enterprise deployment platforms can then transform privileged access into distributed execution. Data can be staged and exfiltrated before the encryptor ever reaches its targets.

That changes the point at which defenders should define a ransomware incident. A .medusa extension is evidence of impact, not the beginning of compromise. If domain credentials, remote-management infrastructure, or deployment systems have already been lost, removing the ransomware binary addresses only the most visible stage of a much larger intrusion.

Why This Threat Matters

  • The edge-to-impact window can collapse quickly. Internet-facing management and file-transfer systems can move from disclosed exposure to active exploitation faster than conventional patch cycles.
  • Legitimate remote tools can become attacker infrastructure. RMM, tunneling, RDP, PsExec, and WMI are not malicious by default. Their authorization, provenance, execution context, and subsequent behavior determine the risk.
  • Identity compromise changes the scope of recovery. LSASS dumping, persistent credential collection, and theft of Active Directory material can give attackers access that survives endpoint cleanup.
  • Administrative infrastructure multiplies execution. GPO and deployment platforms can distribute attacker-controlled changes across an environment far faster than host-by-host movement.
  • Exfiltration can precede encryption. Recovering encrypted systems does not undo data already staged or transferred.
  • Ransomware is the business event, not necessarily the first security event. Earlier callbacks, tunnels, credential access, policy changes, and deployment edits provide more valuable opportunities to interrupt the operation.

Where Defensive Control Must Operate

Defense has to operate across the same control planes the attacker uses.

Xcitium Vulnerability Assessment helps identify exposed services, vulnerable infrastructure, and patch gaps at the edge. Xcitium ITDR addresses the identity pivot by surfacing abnormal authentication and privileged identity activity as credential compromise expands attacker reach.

When the operation moves into scripts, unknown payloads, persistence, post-exploit tooling, and ransomware execution, Xcitium Advanced EDR, powered by Xcitium’s patented Zero-Dwell platform adds the execution layer. Execution Governance governs what unknown execution may do at runtime before trust exists, rather than waiting for the final encryptor to define the incident.

Recover the Control Plane, Not Just the Endpoints

Once Active Directory, RMM infrastructure, GPO, or enterprise deployment systems have been reached, recovery cannot be reduced to deleting malware and restoring encrypted hosts. Privileged credentials, unauthorized remote access, policy changes, deployment jobs, persistence, backup access, and surviving administrative paths must be treated as part of the same compromise.

The ransomware stage begins long before encryption. The strongest defensive opportunity is therefore before the attacker turns stolen access into enterprise-wide execution.

Like what you see? Share with a friend.

Move Away From Detection With Patented Threat Prevention Built For Today's Challenges.

No one can stop zero-day malware from entering your network, but Xcitium can prevent if from causing any damage. Zero infection. Zero damage.

Book a Demo