Skip to main content
Back to Blog
CybersecurityRansomwareCritical InfrastructureOT SecurityIncident ResponseCyberSecurityThreatIntelInfosecCyberthreats

What the Medusa Ransomware Advisory Means for Critical-Infrastructure Operators

Eldar Aydayev· CEO, Aydahwa Enterprise October 5, 2026 10 min read
What the Medusa Ransomware Advisory Means for Critical-Infrastructure Operators

A ransomware crew just crossed 500 critical-infrastructure victims

On 19 August 2026, CISA, the FBI and MS-ISAC refreshed their joint advisory on Medusa ransomware. The updated number is worth sitting with: more than 500 organisations across critical infrastructure have been hit since the group surfaced in June 2021, drawn from FBI casework running through April 2026. The victim list reads like a map of everything a modern economy depends on, healthcare, defence, manufacturing, government services, IT and financial services, with education, insurance and law firms alongside them.

We work with operators in exactly these sectors across the UAE and the wider Gulf, and the advisory does not describe anything exotic. Medusa gets in through the same doors that have been open for years: a convincing phishing email, or an internet-facing appliance that was a few days late getting patched. What makes the group effective is discipline, not novelty. That is also what makes it beatable, provided you treat the fundamentals as an operational commitment rather than a line item in a policy document.

This piece walks through what Medusa actually does, why critical infrastructure and operational technology keep absorbing the damage, and the specific controls that break the attack at each stage. The advice maps to frameworks you are likely already accountable to, NIST CSF, ISO 27001, the CIS Controls, PCI-DSS where card data is in scope, and in this region the UAE Information Assurance Standards and Dubai's ISR.

How Medusa operates

Medusa runs as ransomware-as-a-service. Since early 2023 it has used an affiliate model: a core team maintains the malware and handles ransom negotiation, while affiliates buy or broker the initial break-in and carry out the intrusion. Access to a target changes hands for anywhere between 100 dollars and a million, depending on the organisation. That division of labour matters, because it means the people breaking into your network are specialists who do nothing else all day.

The initial access playbook has two reliable plays. The first is phishing to harvest credentials. The second, and the one that catches larger organisations, is exploiting known vulnerabilities in internet-facing software before the patch window closes. The advisory names remote-access and file-transfer products that keep showing up in real intrusions, including ScreenConnect, Fortinet FortiClient EMS, Fortra GoAnywhere and BeyondTrust. One detail from the update deserves a highlighter: Medusa affiliates have weaponised newly disclosed exploits within 24 hours of publication. Your patch SLA for edge devices is not a monthly cadence anymore. It is a race measured in hours.

Once inside, the group lives off the land. Rather than dropping obvious malware, affiliates lean on tools that are already present or that blend in, PowerShell, Mimikatz for credential theft, and legitimate remote-access utilities like AnyDesk and SimpleHelp. They move laterally, escalate privilege, and take their time mapping the environment. Before anything is encrypted, they exfiltrate data so they can run double extortion, encrypt the files and separately threaten to publish what they stole. Victims are pushed to make contact within 48 hours, and the group has been observed disabling endpoint security tools on the way to detonation.

The attack path, stage by stage

The reason Medusa is worth studying is that its intrusion is linear and well documented, which means every stage has a corresponding control that stops the next one from happening. This is the single most useful way to think about ransomware defence: not as one wall, but as a series of checkpoints where a well-run team gets multiple chances to catch the intruder before the damage is irreversible.

Diagram mapping the four stages of a Medusa ransomware intrusion to the control that stops each one: initial access via phishing and unpatched appliances is stopped by phishing-resistant MFA and 24-hour edge patching; escalation and lateral movement using living-off-the-land tools is stopped by network segmentation and least privilege; data exfiltration for double extortion is stopped by egress filtering and EDR detection; and final encryption and extortion is contained by offline, immutable, tested backups and a rehearsed incident runbook.The pattern holds for almost every ransomware family we respond to, not just Medusa. An affiliate who gets a foothold but hits phishing-resistant multi-factor authentication cannot reuse the credentials they phished. One who lands on a patched edge appliance loses their fastest route in. One who moves laterally into a properly segmented network finds far less to reach. And an operator who exfiltrates data still cannot force a ransom payment if the victim can restore cleanly from backups the attacker never touched. Each control buys back a stage.

Why critical infrastructure keeps paying the price

Enterprises with mature IT security still get hit, and the reason usually lives in the gap between IT and operational technology. In an OPSWAT commentary attached to the recent reporting, the recurring theme was a lack of threat awareness inside OT environments, the plant networks, building management systems, industrial controllers and the appliances that run physical operations. These systems were designed for uptime and safety, not for a threat model where an attacker weaponises a CVE within a day.

Three structural problems come up again and again in our assessments. OT networks are often flat, so once an attacker is in, there is little to stop them reaching a controller from a compromised laptop. Patching is genuinely hard when a device cannot be taken offline without halting production, which leaves known-vulnerable systems exposed for months. And the boundary between the corporate network and the plant floor is frequently softer than the architecture diagram suggests, with a forgotten jump host or a vendor remote-access tool bridging the two.

The aviation disruption across Europe in September 2025 is a useful illustration of how this cascades. ENISA confirmed that ransomware against a third party, the Collins Aerospace MUSE check-in and boarding software, was enough to ground normal operations at Heathrow, Brussels and Berlin, forcing airlines back to manual check-in for days. Nobody breached the airports directly. A supplier's compromise became the airports' outage. If your operations depend on a vendor's platform, that vendor's security posture is part of yours, and it belongs in your risk register whether or not you have visibility into it.

The controls that actually blunt this

Below is the mapping we use when we help a client translate an advisory like this into work that can be assigned and tracked. It ties each Medusa technique to the control that counters it and the framework reference an auditor will recognise. None of this is exotic. The value is in doing it thoroughly and proving it, rather than assuming it is handled.

What Medusa doesControl that counters itFramework reference

Phishes credentials for remote access

Phishing-resistant MFA (FIDO2 or certificate-based) on every external service and VPN

NIST CSF PR.AA; CIS Control 6; ISO 27001 A.5.17

Exploits internet-facing appliances within 24 hours of disclosure

Asset inventory of all edge systems and an emergency patch SLA measured in hours, not weeks

NIST CSF ID.AM / PR.PS; CIS Controls 1, 7

Lives off the land with PowerShell and remote-access tools

Application control, PowerShell logging and constrained language mode, allowlisting of remote-access software

NIST CSF DE.CM; CIS Control 2; ISO 27001 A.8.19

Moves laterally across flat networks

Segmentation between IT and OT, least-privilege access, tiered administration

NIST CSF PR.AC; CIS Control 4; IEC 62443 zones and conduits

Exfiltrates data for double extortion

Egress filtering, DLP on sensitive stores, EDR tuned to detect staging and archiving

NIST CSF PR.DS / DE.AE; CIS Control 3

Disables security tools before encrypting

Tamper protection on EDR, alerting on agent shutdown, backups outside the domain's blast radius

NIST CSF PR.PT; CIS Control 10

Encrypts and demands payment in 48 hours

Offline, immutable, regularly tested backups plus a rehearsed incident-response runbook

NIST CSF RC.RP; CIS Control 11; ISO 27001 A.5.30

Backups are the control that decides the outcome

If you fix only one thing after reading this, make it backups, because they are what turns a catastrophe into an expensive bad week. Double extortion is designed to defeat backups as a strategy, the attacker assumes you can restore, so they steal data to keep leverage even after you recover. That is real, but it changes the negotiation, not the technical outcome. An organisation that can restore does not have to pay to get its operations back. It faces a data-exposure problem, which is serious, rather than a total-shutdown problem, which is existential.

The qualifier that matters is "usable." We have watched more than one recovery stall because the backups were reachable from the same domain the attacker owned, and got encrypted too, or because nobody had actually run a full restore under time pressure. Backups need to be offline or immutable, held outside the production identity boundary, and tested with a real restore on a schedule. A backup you have never restored is a hypothesis, not a control.

A prioritised sequence for the next 90 days

When we run a ransomware-readiness engagement, we sequence the work so the highest-impact, lowest-cost items come first. If you are starting from an uneven baseline, this order gives you the most risk reduction per week of effort.

  1. Inventory every internet-facing system, VPN, remote-access gateway, file-transfer appliance and management interface. You cannot patch or monitor what you have not listed, and edge exposure is Medusa's fastest way in.
  2. Put phishing-resistant MFA on all external access and privileged accounts. Turn off legacy authentication protocols that silently bypass it.
  3. Define an emergency patch process for edge devices with a target measured in hours, and rehearse it against the next critical CVE rather than waiting for a real incident to test it.
  4. Verify your backups are offline or immutable, sit outside the production domain, and can be fully restored. Schedule a timed restore test and record how long it actually takes.
  5. Segment IT from OT and enforce least privilege at the boundary. Even coarse segmentation dramatically shrinks what a single compromised host can reach.
  6. Enable tamper protection and shutdown alerting on your EDR, and turn on PowerShell and command-line logging so living-off-the-land activity leaves a trail.
  7. Write and rehearse an incident-response runbook, including who declares an incident, how you isolate, and how you communicate with regulators and customers. Under the UAE IA Standards and sector rules, timely notification is an obligation, not a courtesy.

You will notice how much of this is process and discipline rather than new tooling. Most organisations we assess already own capable security products. The gap is almost always in configuration, coverage and rehearsal, the unglamorous work that decides whether the tools you paid for actually fire when it counts.

How Aydahwa Enterprise can help

Aydahwa Enterprise is an IT infrastructure and cybersecurity firm based in Dubai, working with operators across banking, telecom and critical infrastructure in the UAE and the GCC. Our team holds credentials including the Microsoft Cybersecurity Architect Expert certification, and we build to the standards this article references, NIST CSF, ISO 27001, PCI-DSS, SOC 2 and the CIS Benchmarks, alongside the UAE Information Assurance Standards and Dubai's ISR where they apply.

If the Medusa advisory made you want a clear read on where you actually stand, that is the work we do. We run ransomware-readiness and OT security assessments that produce a prioritised, costed plan rather than a generic checklist, and we can help implement the controls, from MFA rollout and network segmentation to backup architecture and incident-response rehearsal. You can read more about our cybersecurity services, our cloud security and migration work, and our managed IT support.

Two quick starting points cost you nothing: our cyber security self-assessment gives you a fast baseline, and the cybersecurity readiness checklist lets you check your posture against the controls above. When you want a hands-on review of your environment, get in touch and we will scope it with you.

Share

Need expert guidance?

Our cybersecurity and IT consultants can help you implement the strategies discussed in this article.

Call UsWhatsAppBook