Medusa Advisory: Defender Takeaways on Affiliates and Exploits
Medusa has impacted over 500 organizations across critical infrastructure since 2021, shifting to an affiliate RaaS model in early 2023.
- Affiliates...

Created by Eduardo Silva
Timely CTI news for SOC analysts, incident responders, and threat hunters in enterprise environments
Explore the latest content tracked by Enterprise Threat Intel
Medusa has impacted over 500 organizations across critical infrastructure since 2021, shifting to an affiliate RaaS model in early 2023.
Ransomware affiliates and China-linked APTs are integrating AI into live operations for speed, while keeping core development human-driven.
-...
Medusa ransomware has added hundreds of victims since March 2025 by paying access brokers $100 to $1 million, with premiums for exclusive work.
-...
Regional APTs are pivoting from mass phishing to stealthy campaigns focused on diplomatic, military, and critical infrastructure targets across...
Ransomware gangs are actively exploiting a high-severity Windows Task Host vulnerability, CISA confirms. SOC and IR teams should treat this as patch priority given the confirmed active exploitation since at least April.
Clop operators built a custom Java web shell specifically for PTC Windchill and FlexPLM servers, with built-in capabilities to decrypt credentials, enumerate file repositories, and steal targeted data.
A ransomware affiliate is emailing victims directly, claiming to have breached RaaS groups and offering file recovery plus data deletion for...
Medusa ransomware operators have struck more than 500 victims as of April 2026, up from 300 the prior year, with heavy focus on healthcare.
Key...
Akira operators now force Windows systems into Safe Mode after direct AV interference often fails and triggers quarantines.
The Iran-linked campaign against U.S. drinking water and wastewater systems has grown from seven to at least twelve states, with the first documented...
This week's activity shows attackers exploiting exposed services and unpatched flaws for initial access, then pivoting quickly.
Chinese APT groups are expanding beyond traditional espionage into AI-augmented lures, rapid VMware exploitation, and kernel-level stealth.
-...
This integration feeds Nozomi OT telemetry and asset data directly into Sophos Fusion.
S2W's H1 2026 report recorded 158 state-sponsored incidents from North Korea, Russia, and China — a 7.5% rise from 147 the prior period.
China's...
North Korea conducted 99 AI and deepfake attacks targeting South Korea in the first half of 2026, per the '2026 First Half Threat Trends Report on...