Medusa: The Ransomware Exploiting Zero-Days and Striking in 24 Hours — From Hospitals to the Uffizi
On April 6, 2026, Microsoft published an analysis that redefines the threat level of Medusa ransomware. The group — active since 2021 and already responsible for the attack on Florence's Uffizi Gallery in February 2026 — is exploiting zero-day vulnerabilities up to a week before their public disclosure, and completing the entire attack chain in just 24 hours.
Zero-Days Before Disclosure: Medusa's Time Advantage
Microsoft documented two specific CVEs exploited by Medusa before public disclosure: CVE-2026-23760 in SmarterMail and CVE-2025-10035 in GoAnywhere Managed File Transfer. In both cases, Medusa weaponized the vulnerabilities approximately one week before they became public, with CISA confirming their use in ransomware attacks.
The pre-disclosure exploitation window is Medusa's most dangerous advantage. When a vulnerability isn't yet public, no patches exist, no IDS signatures exist, no CISA advisories exist. Defenders are blind. Medusa strikes in this window — and by the time the patch arrives, data has already been exfiltrated and systems encrypted.
From Initial Access to Ransomware in 24 Hours
Microsoft reports cases where Medusa operators complete the entire attack cycle — initial access, persistent account creation, lateral movement, data exfiltration, and ransomware deployment — in just 24 hours. The average spans 5-6 days, but the ability to compress the operation into one day demonstrates exceptional automation and preparation.
Tools used are deliberately "legitimate": ConnectWise ScreenConnect, AnyDesk, and SimpleHelp — remote management software that many organizations already use or don't block. This tactical choice makes detection extremely difficult: traffic generated is indistinguishable from a system administrator performing remote maintenance.
Victims: Healthcare, Culture, Education
Confirmed victims include the University of Mississippi Medical Center and Passaic County, New Jersey. The geographic scope extends to Australia, the United Kingdom, and the United States. Primary sectors are healthcare, education, professional services, and finance. In Italy, Medusa was responsible for the Uffizi Gallery attack on February 1, 2026, and the simultaneous La Sapienza University attack.
Group Profile: Russia, North Korea, or Both?
Medusa attribution is complex. Analysts assess the group operates from Russia based on CIS target avoidance, Russian-language forum activity, and Cyrillic script in operational tools. However, recent Symantec research revealed that North Korean Lazarus members deployed Medusa ransomware in at least one documented case.
Lazarus involvement in Medusa deployment indicates operational convergence between Russian cybercrime and North Korean espionage that drastically complicates attribution and response.
Context: FBI Reports $17.6 Billion in Cyber Losses for 2025
Medusa's escalation fits within a macroscopic picture documented by the FBI IC3 annual report: in 2025, cyber-enabled fraud losses reached $17.6 billion. Ransomware generated 3,611 complaints for over $32 million in direct losses. The FBI identified 63 new ransomware variants, with 14 of 16 U.S. critical infrastructure sectors targeted. Cryptocurrency-related losses reached $11.3 billion, and AI-based fraud generated $893 million across 22,000 reports.
Operational Recommendations
- 1.Absolute priority patch management: Medusa exploits the pre-patch window. Implement automatic patching for critical systems and monitor CISA advisories before CVEs are even assigned.
- 2.Remote access tool audit: verify all ConnectWise, AnyDesk, and SimpleHelp installations. Remove unauthorized instances and monitor legitimate ones for anomalous patterns.
- 3.Account creation monitoring: Medusa creates user accounts immediately after initial access. Implement alerts on any unauthorized account creation, especially outside business hours.
- 4.Network segmentation and offline backups: in a 24-hour access-to-ransomware scenario, segmentation is the only defense that can limit impact. Backups must be offline and regularly tested.
- 5.Internal communications protection: data exfiltration occurs before ransomware deployment. End-to-end encrypting critical communications reduces the value of exfiltrated data.
- 6.NIS2 compliance verification: the directive imposes specific risk management, incident notification, and business continuity obligations. Penalties reach 10 million euros.
Conclusion
Medusa represents the most dangerous ransomware evolution in 2026: a group combining pre-disclosure vulnerability intelligence with extreme operational speed and indiscriminate targeting of healthcare, culture, and education. For every organization, the question is not if Medusa will strike, but when. And with 24 hours from access to ransomware, "when" could be today.
Sources: Microsoft Threat Intelligence (Medusa analysis, April 6, 2026), CISA (CVE-2026-23760 and CVE-2025-10035 confirmation), Symantec (Lazarus-Medusa connection), FBI IC3 (2025 annual report, $17.6B), The Record, BleepingComputer.