Skip to content

Meduza

Meduza is an information-stealing malware family (infostealer/credential-harvesting malware) active since at least 2023.

Profile source: Mallory opens in a new tab

Meduza

Family profile

Meduza is an information-stealing malware family (infostealer/credential-harvesting malware) active since at least 2023. Reporting in the provided content describes it as designed to steal credentials, cryptocurrency wallets, and other sensitive information from compromised Windows systems. Additional cited research states it can collect browser credentials, cookies, histories, bookmarks, and autofill data from more than 100 browsers; target password managers and 2FA browser extensions; steal from more than 100 cryptocurrency wallet types including browser extensions and desktop applications; and extract data from applications such as Discord, Telegram, email clients, and VPNs. It also gathers host information including hardware details, installed software, IP addresses, time zones, and screenshots.

The malware is consistently referenced as a stealer/infostealer and has been observed in broader criminal delivery chains. The content notes attempts to deploy Meduza via NetSupport RAT in the TA569-linked "Horns&Hooves" email campaign, indicating phishing-driven initial access and follow-on payload delivery. Meduza is also listed among malware families that have successfully bypassed App-Bound Encryption. Splunk detection content further states that Meduza has abused VaultCLI.dll to extract credentials from the Windows Credential Vault, mapping to Windows Credential Manager theft behavior.

Infrastructure reporting in the content links Meduza operations to Russia-based bulletproof hosting provider Aeza Group, which U.S. authorities sanctioned for enabling malware and ransomware actors. Multiple references specifically associate Aeza infrastructure with the Lumma, Meduza, and RedLine infostealers. The content also mentions similarities between Meduza/Aurora Stealer targeting patterns and a separate custom malware campaign, but does not establish they are the same malware family.

Law-enforcement reporting in the provided material states that Russian authorities arrested three suspects believed to have created, sold, distributed, and deployed the Meduza infostealer. Russian officials linked the operation to an attack against a government institution in the Astrakhan region and said the suspects had worked on Meduza for about two years. The same reporting says the suspects also developed another malware strain intended to disable security tools and build botnets.

High-confidence behavioral and targeting details directly supported by the content therefore characterize Meduza as a Russian-linked credential and information stealer used in criminal operations, capable of harvesting browser and application data, cryptocurrency wallet information, Windows Credential Vault data, and broad host reconnaissance, with observed use in phishing-enabled intrusion chains and infrastructure ties to sanctioned bulletproof hosting.

Reported operators

Threat actors

2 named in public reporting
Scattered Spider

Collection Atomic, Vidar, Meduza, Raccoon, Snaffler, Hekatomb, Lumma, DBeaver, MongoDB Compass, Azure SQL Query Editor, Cerebrata, FiveTran, Ave-Maria

Indrik Spider

In a number of cases, we observed attempts to use NetSupport RAT to install stealers such as Rhadamanthys and Meduza.

Exploited software

Vulnerabilities linked to Meduza

1 CVEs

MITRE ATT&CK

Meduza in ATT&CK

12 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.