Skip to content
Deep Dive high HealthcareeducationFinanceprofessional-servicesmanufacturing

Medusa Ransomware: The 500-Victim Operation Using a CrowdStrike Lookalike to Kill EDR

Executive Summary

Medusa is a ransomware-as-a-service operation that has logged more than 500 confirmed victims since its emergence in 2022, with a victim count exceeding 300 critical infrastructure targets by March 2025. CISA, the FBI, and MS-ISAC issued a joint advisory (AA25-071A) as the group accelerated into healthcare, education, manufacturing, legal, and insurance at scale. The operation’s operators — referred to as Spearwing in Picus research and Storm-1175 by Microsoft — maintain the encryptor, negotiation infrastructure, and the Medusa Blog leak site, while affiliates conduct the intrusions and split ransom proceeds. Affiliates have access to a BYOVD toolkit centred on ABYSSWORKER, a signed kernel driver engineered to disable endpoint protection at ring-zero before encryption begins.

Two developments in 2025-2026 make Medusa more significant than its victim count alone suggests. First, the ABYSSWORKER driver represents a level of anti-EDR investment previously associated primarily with nation-state tooling. Second, Symantec and Carbon Black researchers confirmed in 2026 that North Korea’s Lazarus Group — specifically the Stonefly subgroup, also tracked as Andariel — is deploying Medusa ransomware in targeted extortion campaigns against US healthcare entities and a Middle East organisation. A criminal RaaS being weaponised by a nation-state operator for financial and intelligence gain is a significant development in how threat categories blur.

Group Profile and RaaS Structure

Medusa operates on the standard contemporary RaaS model: a core team builds and maintains the tooling, and affiliates carry out intrusions in exchange for a percentage of ransom proceeds. What sets Medusa’s affiliate recruitment apart is the scale of advertised access payments — the group has posted recruitment offers on cybercriminal forums ranging from $100 to $1 million per valid network access, pricing that reflects how central high-quality initial access is to the model’s economics.

The negotiation interface provides victims with a countdown timer; when it expires, exfiltrated data is published on the Medusa Blog. The group also adds a third pressure mechanism in some cases: direct DDoS attacks against the victim organisation during negotiations, creating operational disruption on top of the data leak threat. This triple-extortion approach — encryption, data leak, DDoS — distinguishes Medusa from groups that still rely purely on the first two.

Ransom demands in documented cases have ranged from tens of thousands of dollars to $15 million, calibrated to victim revenue and the sensitivity of exfiltrated data. The group has shown little sector restraint, targeting hospitals during patient care periods — behaviour that has drawn specific FBI and CISA commentary.

Initial Access: Vulnerability Exploitation and Broker Networks

Medusa affiliates predominantly obtain initial access through one of two routes: direct exploitation of unpatched public-facing systems, or purchase of credentials from initial access brokers who have already established a foothold.

The CISA advisory specifically names two vulnerabilities as primary exploitation vectors. CVE-2024-1709 is a critical authentication bypass in ConnectWise ScreenConnect, a widely deployed remote monitoring and management tool, carrying a CVSS score of 10.0. CVE-2023-48788 affects Fortinet FortiClient EMS, a SQL injection vulnerability in the client’s web management interface that allows unauthenticated remote code execution.

Both represent the recurring pattern in ransomware initial access: vulnerabilities in remote access and management software that provide a direct path to administrative credentials. ConnectWise ScreenConnect in particular has been a prolific ransomware entry point across multiple groups because of how broadly it is deployed in managed service provider environments, where a single compromised instance can cascade into dozens of downstream client networks.

Once inside, affiliates rely on remote monitoring and management tools for persistence and lateral movement. AnyDesk is consistently observed alongside PsExec for remote command execution. Credential harvesting uses Mimikatz. Rclone handles data staging and exfiltration, typically to cloud storage services. The toolkit is unremarkable — and deliberately so. These tools are legitimate in many environments, which makes detection harder when BYOVD is about to silence the EDR anyway.

ABYSSWORKER: Kernel-Level EDR Evasion

ABYSSWORKER is the element of the Medusa toolkit that warrants the most sustained analyst attention. Identified and publicly documented by Elastic Security Labs and Halcyon in 2025, the driver is a signed Windows kernel module that strips endpoint protection at the operating system level before the ransomware encryptor executes.

The driver file is named smuol.sys. The filename choice is deliberate: it mimics CrowdStrike Falcon’s legitimate kernel component CSAgent.sys, making a casual review of driver inventory less likely to flag it. The signing certificates are stolen or revoked credentials from Chinese companies — not forged, but acquired through abuse of the legitimate certificate ecosystem. Windows will load a driver signed with a valid code-signing certificate, even if that certificate has since been revoked, if the revocation check fails or is bypassed.

At ring-zero, ABYSSWORKER exposes a Device I/O Control interface. Affiliates interact with it via user-mode code that sends IOCTLs to the driver. The documented capability set includes termination of specific processes by name or PID (targeting EDR and AV processes), removal of kernel callbacks registered by security products (which is how EDR tools receive notifications of process creation, file writes, and network activity), and manipulation of kernel object attributes to blind monitoring software. The driver does not need to stay loaded after the EDR is dead — it can be unloaded and deleted, removing itself from the driver inventory before forensic collection begins.

Elastic’s research identified ABYSSWORKER delivered as part of a loader chain: the Medusa encryptor is packed with HeartCrypt, a packer-as-a-service that has been observed in multiple ransomware operations. HeartCrypt-packed payloads are designed to complicate static analysis. The full chain is: credential access, RMM for lateral movement, ABYSSWORKER BYOVD to kill EDR, HeartCrypt-packed encryptor deployment.

The PowerShell command history wipe observed in Medusa intrusions — executed before the encryptor runs — is a complementary evasion step. It removes evidence of the command-line activity used to orchestrate the attack from the victim’s PowerShell log.

The Lazarus Connection

In 2026, Symantec and Carbon Black published research confirming that Stonefly, a Lazarus Group subgroup also tracked as Andariel, is deploying Medusa ransomware in targeted extortion campaigns. The specific targets identified include US healthcare entities and a Middle East organisation, reflecting Stonefly’s documented history of targeting those sectors.

This development is significant on several levels. Stonefly has a prior history of deploying bespoke ransomware: Maui ransomware, attributed to North Korean operators by CISA, specifically targeted US healthcare. The move to Medusa represents a shift from bespoke tools to a commercial RaaS — a choice that provides operational deniability (the malware is available to hundreds of affiliates globally, which complicates attribution) while reducing the development burden of maintaining a custom encryptor.

The broader implication for defenders is that Medusa victims may include both criminal affiliate intrusions and North Korean state-sponsored operations. The initial access TTPs and post-compromise tradecraft may differ between these two actor types, even when the final payload is identical. A Medusa intrusion that began with a spearphishing lure against healthcare employees, with DPRK-associated infrastructure in the C2 chain, is a materially different incident from a criminal affiliate who bought ScreenConnect access from an IAB.

This is not a theoretical concern. The forensic artifacts available in the victim environment — C2 infrastructure, post-compromise tools, targeting specificity — may distinguish the two, but only if the incident responder is looking for those indicators. Attribution ambiguity works in the operator’s favour.

Targeting and Victim Analysis

Medusa’s sector targeting spans healthcare, education, manufacturing, legal, insurance, and technology. The CISA advisory notes that the group has attacked more than 300 critical infrastructure targets. The victim profile skews toward mid-market organisations — large enough to have meaningful data and revenue, small enough to have less mature security programmes than enterprise.

Geographic concentration in documented 2026 activity includes North America and Western Europe, with notable healthcare sector victims in both. The Lazarus/Stonefly-attributed campaigns extend targeting to the Middle East. Manufacturing and legal sector victims are spread more broadly across geographies, consistent with opportunistic access broker procurement rather than targeted geographic operations.

The Medusa Blog has published data from victims in at least 40 countries as of mid-2026. The group does not appear to maintain geopolitical exclusions comparable to Russian-affiliated groups that avoid targeting CIS countries.

Defensive Implications

The CISA advisory provides specific guidance that maps directly to the observed TTPs:

Patch ConnectWise ScreenConnect and Fortinet FortiClient EMS. CVE-2024-1709 and CVE-2023-48788 remain primary initial access vectors. Both vulnerabilities have patches; any organisation running unpatched versions of these products in 2026 is at material risk.

Implement BYOVD detection. ABYSSWORKER’s delivery and use leaves detectable traces: the driver write to disk, the service creation, the IOCTL calls to kernel-mode processes. Sigma and KQL detection logic targeting these events should be in place. The specific driver filename smuol.sys and the revoked Chinese certificates are IOCs, but ABYSSWORKER variants will use different filenames and certificates. Focus on behaviours rather than static indicators.

Monitor for EDR process termination. Any process that terminates a security product process is worth immediate investigation. Medusa’s BYOVD tooling terminates EDR processes before the encryptor runs — that kill event is your last chance to intervene with visibility intact.

Enable Protected Processes for EDR. Security products that use Windows Protected Process Light (PPL) are significantly harder to kill via BYOVD. Not all EDR products support PPL, and not all BYOVD techniques are blocked by it, but it raises the cost of the attack.

Treat RMM tool execution from unusual parents as high-fidelity. AnyDesk and PsExec spawned from non-standard parent processes, or executing at unusual hours, should trigger investigation. Medusa affiliates use legitimate tools precisely because they blend with normal traffic — context and timing are the signals.

Isolate Medusa-pattern intrusions for attribution investigation. Given the Lazarus/Stonefly deployment of Medusa, incident responders should capture full forensic images and C2 infrastructure indicators. An intrusion that looks like a criminal affiliate may be a nation-state operation. The distinction matters for regulatory notification, insurance coverage, and government engagement.

ABYSSWORKER is not unique to Medusa — the driver-based EDR-kill technique is used across multiple ransomware families. But the specific sophistication of Medusa’s kernel-level tooling, combined with the confirmed state-sponsored adoption of the encryptor, places Medusa in a distinct threat tier for organisations in the targeted sectors.