Skip to content

Medusa

Medusa is a ransomware-as-a-service operation first identified in June 2021, distinct from both MedusaLocker and the unrelated open-source Linux rootkit named Medusa.

Profile source: Mallory opens in a new tab

Medusa

Family profile

Medusa is a ransomware-as-a-service operation first identified in June 2021, distinct from both MedusaLocker and the unrelated open-source Linux rootkit named Medusa. It evolved from a closed operation to an affiliate-based model by at least early 2023. Medusa developers and affiliates use double extortion: they steal data, encrypt victim systems, and threaten public release of the stolen material if ransom demands are not met. Some activity has also been characterized as triple extortion.

Medusa commonly obtains initial access through phishing, stolen credentials and access brokers, and exploitation of newly disclosed internet-facing vulnerabilities, including CVE-2024-1709, CVE-2023-48788, CVE-2025-10035, and CVE-2026-1731. Operators have demonstrated rapid exploitation of public vulnerabilities. Post-compromise activity includes security-product discovery, credential dumping, Active Directory theft, PowerShell-based defense evasion, deletion of shadow copies, termination of security and backup services, use of legitimate remote-access and remote-management tools, lateral movement through RDP and other administrative mechanisms, data staging and archival, and exfiltration. The Windows encryptor uses AES-256 encryption and applies a Medusa-specific extension to encrypted files; Linux and ESXi environments have also been affected.

As of April 2026, Medusa actors had impacted more than 500 victims across critical-infrastructure and commercial sectors. Frequently affected sectors include healthcare and public health, defense industrial base, manufacturing, government, information technology, financial services, education, legal services, and insurance. Healthcare has been a particularly frequent target.

Capabilities

  • Byovd
  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Initial Access
  • Lateral Movement
  • Post Exploitation
  • Reconnaissance

Operational record

24
Indicators
1
YARA rules
2
Ransom notes
11
Leak sites
0 available

Credential Theft

  • Mimikatz

Defense Evasion

  • EDRSandBlast
  • KillAV
  • ThrottleStop driver

Discovery Enum

  • Advanced IP Scanner
  • Navicat
  • PDQ Inventory
  • RoboCopy
  • SoftPerfect NetScan

Exfiltration

  • RClone

LOLBAS

  • BITSAdmin
  • Process Explorer
  • PsExec

Networking

  • Cloudflared
  • FRP
  • Ligolo
  • PuTTY
  • RevSocks

RMM Tools

  • AnyDesk
  • Atera
  • HCL BigFix
  • N-Able
  • PDQ Deploy
  • ScreenConnect
  • SimpleHelp
  • Splashtop
  • eHorus

Published indicators

Telegram

1 total
  • https://t.me/+yXOcSjVjI9tjM2E0

Md5

18 total
  • 983a20479a281a182d33b75c0945e447
  • 4fe99e5dc101170750d8ece6ea066155
  • dc344328208c3481587d0aab1005fcdd
  • 10911494fa52daee0279972f91fded01
  • 24ccd142ff83e8622f00f5443ea5cb2d
  • a6980e543efa40771ed1dcf84b29d732
  • a162a5c5ab72b3783215f52b9edc3680
  • 600371ebab1e29429f06a5b1909056e5
  • 0067679c7033139bcbb273840494b324
  • 602d720f1184d2ad739568cbf6403331

Tox

3 total
  • 4AE245548F2A225882951FB14E9BF87EE01A0C10AE159B99D1EA62620D91A372205227254A9F
  • 061AA6BDE8F6DE6C92F0D6E077359BF6911FCAF80030E82B3A3DB65E63C8011343D34F956FEC
  • AEA72DFCF492037A6D15755A74645C7D8E674E342BACA9F9070A3FB74117EC3143FD6E29BEAC

Email

2 total
  • medusa.support@onionmail.org
  • MedusaSupport@cock.li

Reported operators

Threat actors

14 named in public reporting
UNC3886

На скомпрометированных управляющих Linux-хостах злоумышленники разворачивали набор инструментов для длительного доступа к инфраструктуре жертв. В него входили руткиты Medusa и REPTILE.

Storm-1175

It marks a departure from the Medusa ransomware previously used by the group... Storm-1175’s ransomware activity is similar to the Medusa ransomware campaigns previously attributed to the same hacking group.

Medusa Group

Medusa Ransomware has the capability to detect security solutions for termination or deletion within the victim device using hard-coded lists of strings containing security product executables.

Lazarus

In recent months, the Lazarus Group and its related intrusion set Moonstone Sleet have also been attributed to attacks targeting South Korean and Middle East entities with Qilin and Medusa ransomware.

Moonstone Sleet

In recent months, the Lazarus Group and its related intrusion set Moonstone Sleet have also been attributed to attacks targeting South Korean and Middle East entities with Qilin and Medusa ransomware.

Mythic Likho

Название «Mythic» в имени кластера отражает использование Mythic C2 - открытого фреймворка для post-exploitation с множеством агентов (Apollo, Medusa, Athena).

Blockade Spider

Essentially, OrBit is built from Medusa, an open-source LD_PRELOAD rootkit published on GitHub in December 2022.

Hastalamuerte

Hastalamuerte was an experienced affiliate who had previously worked with Embargo, LockBit, and Medusa before joining Qilin.

Andariel

Sample 1 ( gaze.exe ) is a fully functional Medusa ransomware binary whose XOR-encoded config (key 0x2E ) yields four Tor .onion C2 addresses, a victim-specific negotiation endpoint, and a kill list targeting 50+ enterprise security and backup services.

APT38

Sample 1 ( gaze.exe ) is a fully functional Medusa ransomware binary whose XOR-encoded config (key 0x2E ) yields four Tor .onion C2 addresses, a victim-specific negotiation endpoint, and a kill list targeting 50+ enterprise security and backup services.

Spearwing

Sample 1 ( gaze.exe ) is a fully functional Medusa ransomware binary whose XOR-encoded config (key 0x2E ) yields four Tor .onion C2 addresses, a victim-specific negotiation endpoint, and a kill list targeting 50+ enterprise security and backup services.

EncryptHub

Windows System Network Config Discovery Display DNS ... Medusa Ransomware, Windows Post-Exploitation, Prestige Ransomware, Water Gamayun

Contagious Interview

North Korean state-backed attackers are now using the Medusa ransomware... Medusa, which is operated by the Spearwing cybercrime group, was launched in 2023 and is run as a ransomware-as-a-service.

Pompilus

The North Korea-linked Lazarus Group (aka Diamond Sleet and Pompilus) has been observed using Medusa ransomware in an attack targeting an unnamed entity in the Middle East.

Exploited software

Vulnerabilities linked to Medusa

26 CVEs
CVE-2023-48788 Fortinet FortiClient EMS DB2 Administration Server SQL Injection RCE CVE-2026-1731 Pre-authentication OS Command Injection in BeyondTrust Remote Support and Privileged Remote Access CVE-2024-1709 ConnectWise ScreenConnect Authentication Bypass CVE-2025-10035 Unsafe Deserialization RCE in Fortra GoAnywhere MFT License Servlet CVE-2026-18577 N-able N-central Authentication Bypass and Account Takeover CVE-2023-37679 Unauthenticated RCE in NextGen Mirth Connect <= 4.3.0 CVE-2024-27199 JetBrains TeamCity Relative Path Traversal Authentication Bypass CVE-2024-1708 Path Traversal in ConnectWise ScreenConnect CVE-2024-27198 Authentication Bypass in JetBrains TeamCity On-Premises CVE-2023-43208 Unauthenticated RCE in NextGen Healthcare Mirth Connect CVE-2024-57728 SimpleHelp Zip Slip Arbitrary File Upload Leading to RCE CVE-2024-57727 Unauthenticated Path Traversal in SimpleHelp CVE-2024-57726 SimpleHelp Missing Authorization Privilege Escalation CVE-2024-37085 Authentication Bypass in VMware ESXi Active Directory Integration CVE-2023-21529 Microsoft Exchange Server Deserialization of Untrusted Data RCE CVE-2023-0669 Pre-authentication RCE in Fortra GoAnywhere MFT License Response Servlet CVE-2025-31324 Unauthenticated File Upload RCE in SAP NetWeaver Visual Composer Metadata Uploader CVE-2025-31161 CrushFTP AWS4-HMAC Authentication Bypass CVE-2026-23760 Authentication Bypass in SmarterTools SmarterMail Password Reset API CVE-2023-27351 PaperCut NG/MF Authentication Bypass CVE-2025-52691 Unauthenticated Arbitrary File Upload in SmarterTools SmarterMail CVE-2024-21887 Command Injection in Ivanti Connect Secure and Policy Secure CVE-2023-46805 Ivanti Connect Secure and Policy Secure Authentication Bypass CVE-2023-27350 PaperCut MF/NG SetupCompleted Authentication Bypass RCE CVE-2022-41082 ProxyNotShell RCE in Microsoft Exchange Server CVE-2022-41080 OWASSRF authenticated SSRF in Microsoft Exchange Server

MITRE ATT&CK

Medusa in ATT&CK

137 distinct techniques

Techniques

137 techniques
T1014 Rootkit T1070.006 Timestomp T1036.005 Match Legitimate Resource Name or Location T1036 Masquerading T1059.001 PowerShell T1486 Data Encrypted for Impact T1021 Remote Services T1190 Exploit Public-Facing Application T1078 Valid Accounts T1657 Financial Theft T1133 External Remote Services T1567 Exfiltration Over Web Service T1041 Exfiltration Over C2 Channel T1021.001 Remote Desktop Protocol T1566 Phishing T1070 Indicator Removal T1489 Service Stop T1071 Application Layer Protocol T1003 OS Credential Dumping T1560 Archive Collected Data T1490 Inhibit System Recovery T1105 Ingress Tool Transfer T1074 Data Staged T1537 Transfer Data to Cloud Account T1588.001 Malware T1564.003 Hidden Window T1518.001 Security Software Discovery T1059 Command and Scripting Interpreter T1114 Email Collection T1010 Application Window Discovery T1113 Screen Capture T1056 Input Capture T1056.001 Keylogging T1082 System Information Discovery T1219 Remote Access Tools T1203 Exploitation for Client Execution T1195 Supply Chain Compromise T1027 Obfuscated Files or Information T1574 Hijack Execution Flow T1649 Steal or Forge Authentication Certificates T1213 Data from Information Repositories T1547.001 Registry Run Keys / Startup Folder T1071.001 Web Protocols T1110 Brute Force T1562.001 Disable or Modify Tools T1574.006 Dynamic Linker Hijacking T1106 Native API T1556.003 Pluggable Authentication Modules T1564 Hide Artifacts T1110.003 Password Spraying T1110.001 Password Guessing T1564.009 Resource Forking T1021.004 SSH T1057 Process Discovery T1556 Modify Authentication Process T1059.003 Windows Command Shell T1056.004 Credential API Hooking T1564.001 Hidden Files and Directories T1622 Debugger Evasion T1136 Create Account T1070.004 File Deletion T1140 Deobfuscate/Decode Files or Information T1547 Boot or Logon Autostart Execution T1562 Impair Defenses T1546.008 Accessibility Features T1568 Dynamic Resolution T1040 Network Sniffing T1006 Direct Volume Access T1210 Exploitation of Remote Services T1548.002 Bypass User Account Control T1135 Network Share Discovery T1497 Virtualization/Sandbox Evasion T1112 Modify Registry T1570 Lateral Tool Transfer T1484.001 Group Policy Modification T1505.003 Web Shell T1567.002 Exfiltration to Cloud Storage T1562.004 Disable or Modify System Firewall T1589 Gather Victim Identity Information T1021.002 SMB/Windows Admin Shares T1595 Active Scanning T1543.003 Windows Service T1218.007 Msiexec T1007 System Service Discovery T1046 Network Service Discovery T1098.004 SSH Authorized Keys T1569.002 Service Execution T1047 Windows Management Instrumentation T1053 Scheduled Task/Job T1018 Remote System Discovery T1016 System Network Configuration Discovery T1485 Data Destruction T1020 Automated Exfiltration T1518.002 Backup Software Discovery T1679 Selective Exclusion T1124 System Time Discovery T1027.013 Encrypted/Encoded File T1680 Local Storage Discovery T1083 File and Directory Discovery T1563.001 SSH Hijacking T1559 Inter-Process Communication T1003.003 NTDS T1005 Data from Local System T1555.003 Credentials from Web Browsers T1090 Proxy T1072 Software Deployment Tools T1559.001 Inter-Process Communication: Component Object Model T1675 ESXi Administration Command T1136.002 Create Account: Domain Account T1027.002 Obfuscated Files or Information: Software Packing T1027.010 Obfuscated Files or Information: Command Obfuscation T1070.003 Indicator Removal: Clear Command History T1218.014 System Binary Proxy Execution: MMC T1564.012 Hide Artifacts: File/Path Exclusions T1562.009 Safe Mode Boot T1003.001 OS Credential Dumping: LSASS Memory T1558 Steal or Forge Kerberos Tickets T1033 System Owner/User Discovery T1049 System Network Connections Discovery T1069.002 Permission Groups Discovery: Domain Groups T1087.001 Account Discovery: Local Account T1652 Device Driver Discovery T1045 Exfiltration Over C2 Channel T1048 Exfiltration Over Alternative Protocol T1090.003 Proxy: Multi-hop Proxy T1573.002 Encrypted Channel: Asymmetric Cryptography T1529 System Shutdown/Reboot T1583.006 Acquire Infrastructure: Web Services T1585.001 Establish Accounts: Social Media Accounts T1585.002 Establish Accounts: Email Accounts T1588.002 Obtain Capabilities: Tool T1608.002 Stage Capabilities: Upload Tool T1650 Acquire Access T1553.002 Subvert Trust Controls: Code Signing T1685 Disable or Modify Tools T1686 Disable or Modify System Firewall T1690 Prevent Command History Logging

Reporting

Research mentioning Medusa

Aug 19
Bleeping Computer

CISA: Medusa ransomware hit over 500 critical infrastructure orgs

CISA, the FBI, and HHS issued an updated joint advisory warning that Medusa ransomware operators have compromised more than 500 organizations as of April 2026, with heavy targeting of critical infrastructure and especially healthcare and public health entities. The agencies said the group evolved from a closed operation into a ransomware-as-a-service model in 2023, using double extortion by stealing data before encrypting systems. Officials said Medusa actors can exploit newly disclosed vulnerabilities within 24 hours, and in some cases were observed abusing flaws up to a week before public disclosure. The advisory said Medusa gains access through initial access brokers, reportedly offering up to $1 million for exclusive access, and has exploited vulnerabilities including CVE-2024-1709, CVE-2023-48788, GoAnywhere MFT flaws, and CVE-2026-1731. Once inside, operators use living-off-the-land techniques, credential dumping, stolen or vulnerable drivers, and legitimate remote monitoring and management tools to disable security controls, move laterally, steal sensitive data, and encrypt networks. Authorities also described aggressive extortion tactics such as rapid-payment discounts and paid deadline extensions, while urging organizations to patch quickly, segment networks, enforce phishing-resistant MFA, maintain offline immutable backups, and monitor for unauthorized RMM activity.

Aug 18
Malware News

Medusa ransomware tallies hundreds of new victims, says updated advisory on group’s tactics - Malware News - Malware Analysis, News and Indicators

Aug 18
Data Breaches

Medusa ransomware tallies hundreds of new victims, says updated advisory on group’s tactics - DataBreaches.Net

Aug 18
The Record Media

More than 200 victims of Medusa ransomware identified over the last year, CISA says | The Record from Recorded Future News

Aug 18
Cyber Security News

CISA Warns Medusa Ransomware Hackers Steal Data, Kill Security Tools, and Encrypt Entire Networks

Aug 12
Hookphish

Ransomware Group clop Hits: HONGHE-TECH.COM

The Clop ransomware operation has repeatedly targeted enterprise networks with intrusions that begin with phishing or exploitation of exposed systems, followed by manual lateral movement, credential theft, and domain-wide deployment. Reporting from ANSSI and AhnLab linked earlier campaigns to TA505, describing attacks in which operators used tools such as Cobalt Strike and Mimikatz, encrypted files with .Clop or .CIop extensions, and disrupted business operations at victims including E-Land Group, Software AG, and reportedly Indiabulls Group. Analysts also observed Clop using signed malware components, targeting Active Directory environments, stopping business-critical services before encryption, and in some cases preserving shadow copies depending on the variant. The group increasingly shifted from encryption-only attacks to double extortion and broader data-leak pressure tactics. Clop operators published stolen files on leak sites, demanded multimillion-dollar payments, contacted victims' customers directly to intensify pressure, and were tied to mass data-theft campaigns exploiting managed file transfer flaws such as CVE-2023-0669 in Fortra GoAnywhere MFT, which was linked to theft from about 130 companies. More recent victim listings attributed to Clop include organizations in the U.S., Canada, Peru, China, Taiwan, and Europe across technology, manufacturing, retail, and other sectors, underscoring the group's continued global focus on enterprise-scale ransomware and data-breach operations.

Aug 12
Hookphish

Ransomware Group clop Hits: 9ALTITUDES.COM

Aug 12
Hookphish

Ransomware Group clop Hits: WATERLANDPE.COM

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.