Updated Response to CISA Advisory (AA25-071A): #StopRansomware: Medusa Ransomware

On August 18, 2026, CISA revised Cybersecurity Advisory AA25-071A to provide additional information on the Tactics, Techniques, and Procedures (TTPs) associated with Medusa ransomware. The revised advisory provides further insight into Medusa actors’ post-compromise activity, including credential access, defense evasion, privilege escalation, and discovery across Windows and Linux environments.

AttackIQ previously responded to AA25-071A by leveraging our existing Medusa ransomware attack graph and releasing a dedicated assessment incorporating the TTPs identified in the advisory. This assessment enabled security teams to evaluate the effectiveness of their security controls against behaviors observed in Medusa operations.

In response to the latest revision, AttackIQ has updated the existing assessment with additional scenarios covering the newly reported behaviors. These updates expand coverage across credential access, defense evasion, privilege escalation, and discovery, enabling customers to validate their security controls against the latest TTPs associated with Medusa ransomware.

Updates to [CISA AA25-071A] #StopRansomware: Medusa Ransomware

The updated assessment builds upon the scenarios previously released in response to the advisory and incorporates additional scenarios based on the newly reported Medusa behaviors.

Privilege Escalation

Add Local User to Local ‘Administrators’ Group (T1098): This scenario adds a local user to the local Administrators group using the net localgroup command.

Defense Evasion

Enable System “LocalAccountTokenFilterPolicy” Registry Key using “reg.exe” (T1112): This scenario modifies the LocalAccountTokenFilterPolicy registry value at HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System and sets it to 1, disabling UAC remote token filtering for local accounts and allowing administrative privileges to be retained during remote authentication.

Add Directory to Microsoft Defender Exclusion List using PowerShell (T1562.001): This scenario uses the Add-MpPreference cmdlet to add the %TEMP%\aiq-temp-exclusion\ directory path to the Windows Defender exclusion list.

Discovery

Process Discovery Through Tasklist (T1057): This scenario enumerates processes running on the target asset through the tasklist Windows utility. The results are saved to a file in a temporary location.

Enumerate Trusted Domains via nltest (T1482): This scenario executes the command nltest /trusted_domains to obtain domain trust relationships, which allow a domain to access resources based on another domain’s authentication procedures.

Enumerate Loopback via “net view” Command (T1018): This scenario executes net view \127.0.0.1 on the asset under test, directing the command at the loopback address as a benign, self-contained stand-in for a targeted host. The net view command is a built-in Windows network utility that displays the shared resources that host makes available over the network.

Opportunities to Expand Emulation Capabilities

In addition to the released assessment template, AttackIQ recommends the following existing scenario to extend the emulation of the capabilities exhibited in this advisory:

Dump Active Directory Database using Volume Shadow Copy via vssadmin.exe (T1003.003): This scenario creates a Shadow Copy using vssadmin.exe, retrieves the NTDS.dit file and SYSTEM registry hive from the shadow copy, and uses the hive to support decryption of the credentials contained in the Active Directory database.

Strengthening Medusa Ransomware Defense

The latest updates to the Medusa ransomware assessment expand AttackIQ’s coverage of the behaviors identified by CISA, providing security teams with additional opportunities to validate their prevention and detection capabilities across the attack lifecycle. AttackIQ recommends running the following assessments to evaluate security controls against Medusa ransomware activity:

  • (Updated) [CISA AA25-071A] #StopRansomware: Medusa Ransomware
  • [Malware Emulation] Medusa Ransomware – 2024-01 – Associated Tactics, Techniques and Procedures (TTPs)
  • Medusa Ransomware – 2024-01 – Complete Infection Chain

By continuously updating assessments in response to newly identified adversary behaviors, organizations can evaluate whether their security controls remain effective against evolving ransomware operations. The updated [CISA AA25-071A] #StopRansomware: Medusa Ransomware assessment enables organizations to test their security posture against the latest TTPs associated with Medusa ransomware and identify opportunities to strengthen their defenses.

Wrap Up

In summary, these emulations will evaluate security and incident response processes and support improvements to your security control posture against the behaviors exhibited by Medusa ransomware. With data generated from continuous testing and use of these assessment templates, you can focus your teams on achieving key security outcomes, adjust your security controls, and work to elevate your total security program effectiveness against a known and dangerous threat. AttackIQ is the industry’s leading Continuous Threat Exposure Management (CTEM) platform, enabling organizations to measure true exposure, prioritize risk, and disrupt real-world attack paths. By moving beyond static vulnerability data, AttackIQ operationalizes CTEM by continuously validating exposures against real adversary behavior and defensive controls. The platform connects vulnerabilities, configurations, identities, and detections into adversary-validated attack paths—quantifying the likelihood of attacker movement and impact. This evidence-based approach empowers security leaders to focus on what matters most, optimize defensive investments, and strengthen resilience through threat-informed, AI-driven security operations.

Ayelen Torello

Ayelen Torello creates adversary emulations to enable customers to test and validate their security controls. Ayelen has extensive experience in the CTI field and is a results-driven professional with a passion for malware analysis and conducting thorough investigations.

Related Posts