THE ransomware-as-a-service group Medusa has recently updated its tactics and has reportedly added hundreds of victims in over a year, according to a new U.S. government advisory. They are utilizing access brokers, who are compensated between $100 to $1 million, depending on their exclusivity with Medusa. However, many brokers work with multiple ransomware variants simultaneously.
This updated advisory expands on findings from March 2025 and includes details on software vulnerabilities exploited by Medusa, such as flaws in Fortra GoAnywhere and BeyondTrust software.