The Medusa ransomware-as-a-service group is aggressively expanding its reach by adopting new tactics to infiltrate systems, as detailed in an updated advisory by the U.S. Cybersecurity and Infrastructure Security Agency, FBI, and Health and Human Services Department. This group, known for its opportunistic attacks, has significantly increased its number of victims in just over a year, from more than 300 in March 2025 to over 500 by April of this year. Medusa primarily targets entities with unpatched software vulnerabilities, particularly in the Healthcare and Public Health sector. The advisory notes that Medusa does not create its own exploits but quickly capitalizes on newly announced or undisclosed vulnerabilities. Their method involves compensating access brokers, with payments ranging from $100 to $1 million, to gain entry into networks. Most brokers work with multiple variants, though Medusa pays a premium for exclusivity. Once inside a network, Medusa actors utilize legitimate tools and techniques to remain undetected, such as remote monitoring software and the Remote Desktop Protocol, to move laterally within the system. They then proceed with credential access, data exfiltration, and deploying ransomware. Recent insights from Microsoft, Symantec, and Carbon Black have highlighted the involvement of North Korean hackers using Medusa to target the healthcare sector. Organizations are urged to patch software vulnerabilities promptly to reduce the risk of becoming the next victim.