Credential Theft
- Mimikatz
Medusa is a financially motivated ransomware-as-a-service operation first identified in 2021 that has targeted hundreds of organizations across healthcare, education, legal, insurance, technology, manufacturing, and other critical sectors.
Profile source: Mallory opens in a new tabMedusa
Medusa is a financially motivated ransomware-as-a-service operation first identified in 2021 that has targeted hundreds of organizations across healthcare, education, legal, insurance, technology, manufacturing, and other critical sectors. It operates a double-extortion model in which operators or affiliates steal data before encrypting systems and then threaten public disclosure through a leak site if victims do not pay. Medusa began as a closed operation and later adopted an affiliate model, while core operators reportedly retained centralized control over negotiations.
Medusa commonly gains initial access through purchased footholds from initial access brokers, credential-phishing, and exploitation of vulnerable internet-facing services. Public reporting has linked the group to exploitation of ScreenConnect CVE-2024-1709, FortiClient EMS CVE-2023-48788, and SimpleHelp vulnerabilities including CVE-2024-57727 and CVE-2024-57728. In observed intrusions, operators used compromised remote-management infrastructure to hijack agents, redirect management traffic, and establish persistent access.
Post-compromise activity includes use of PowerShell, WMI, RDP, PsExec, Cobalt Strike, built-in Windows tooling, and commercial or legitimate remote-management software for execution, discovery, lateral movement, and staging. Medusa operators have also used network-scanning utilities and deployment tools to expand access across victim environments. Data theft commonly precedes encryption, with exfiltration frequently conducted using Rclone.
A notable feature of Medusa tradecraft is aggressive defense evasion. The operation has been associated with bring-your-own-vulnerable-driver techniques to disable or impair endpoint security products, including use of the ABYSSWORKER kernel driver in campaigns where a packed loader deployed the driver before ransomware execution. Reported behavior also includes terminating services, deleting shadow copies, and clearing PowerShell command history to hinder response and recovery.
On Windows systems, Medusa encrypts files and appends a characteristic extension, then drops a ransom note directing victims to negotiation channels. The operation is distinct from similarly named threats such as MedusaLocker, the Android banking trojan called Medusa, the Mythic agent named Medusa, and the open-source Linux rootkit of the same name.
https://t.me/+yXOcSjVjI9tjM2E0983a20479a281a182d33b75c0945e4474fe99e5dc101170750d8ece6ea066155dc344328208c3481587d0aab1005fcdd10911494fa52daee0279972f91fded0124ccd142ff83e8622f00f5443ea5cb2da6980e543efa40771ed1dcf84b29d732a162a5c5ab72b3783215f52b9edc3680600371ebab1e29429f06a5b1909056e50067679c7033139bcbb273840494b324602d720f1184d2ad739568cbf64033314AE245548F2A225882951FB14E9BF87EE01A0C10AE159B99D1EA62620D91A372205227254A9F061AA6BDE8F6DE6C92F0D6E077359BF6911FCAF80030E82B3A3DB65E63C8011343D34F956FECAEA72DFCF492037A6D15755A74645C7D8E674E342BACA9F9070A3FB74117EC3143FD6E29BEACmedusa.support@onionmail.orgMedusaSupport@cock.liReported operators
Название «Mythic» в имени кластера отражает использование Mythic C2 - открытого фреймворка для post-exploitation с множеством агентов (Apollo, Medusa, Athena).
Since 6 February 2025, S-RM has responded to several incidents involving the ransomware group Medusa, where this group has exploited SimpleHelp vulnerabilities to gain initial access to victims’ infrastructure.
Researchers observed the group deploying Linux rootkits, including REPTILE and MEDUSA, after exploiting vCenter and ESXi vulnerabilities.
North Korea's Lazarus Group targets healthcare orgs with Medusa ransomware
The Medusa ransomware activity, executed by the threat actor group Storm-1175, demonstrates a decisive shift toward exploit-centric, high-velocity intrusion models.
Essentially, OrBit is built from Medusa, an open-source LD_PRELOAD rootkit published on GitHub in December 2022.
Hastalamuerte was an experienced affiliate who had previously worked with Embargo, LockBit, and Medusa before joining Qilin.
Sample 1 ( gaze.exe ) is a fully functional Medusa ransomware binary whose XOR-encoded config (key 0x2E ) yields four Tor .onion C2 addresses, a victim-specific negotiation endpoint, and a kill list targeting 50+ enterprise security and backup services.
Sample 1 ( gaze.exe ) is a fully functional Medusa ransomware binary whose XOR-encoded config (key 0x2E ) yields four Tor .onion C2 addresses, a victim-specific negotiation endpoint, and a kill list targeting 50+ enterprise security and backup services.
Sample 1 ( gaze.exe ) is a fully functional Medusa ransomware binary whose XOR-encoded config (key 0x2E ) yields four Tor .onion C2 addresses, a victim-specific negotiation endpoint, and a kill list targeting 50+ enterprise security and backup services.
Windows System Network Config Discovery Display DNS ... Medusa Ransomware, Windows Post-Exploitation, Prestige Ransomware, Water Gamayun
North Korean state-backed attackers are now using the Medusa ransomware... Medusa, which is operated by the Spearwing cybercrime group, was launched in 2023 and is run as a ransomware-as-a-service.
The North Korea-linked Lazarus Group (aka Diamond Sleet and Pompilus) has been observed using Medusa ransomware in an attack targeting an unnamed entity in the Middle East.
Exploited software
MITRE ATT&CK
Reporting
Attackers compromised the Artlist WordPress subdomain new-blog.artlist[.]io and used it to deliver a sophisticated ClickFix malware campaign that presented visitors with a fake CAPTCHA and tricked them into running PowerShell. The injected JavaScript used an EtherHiding technique, querying a Polygon smart contract to dynamically retrieve the next-stage host auth-code-check[.]info, then downloaded a multi-stage infection chain from the attacker-controlled backend. Researchers traced the intrusion to WordPress credentials stolen from an Israeli freelance developer whose machine had been infected by an infostealer after downloading a pirated copy of Adobe Acrobat Pro DC in 2023. The payload chain reportedly used a password-protected archive, a signed StruSoft/FEM-Design updater, and DLL side-loading to decode shellcode and load a final native RAT that supported encrypted and Tor-backed C2, browser credential theft, keylogging, clipboard and screen access, hidden desktop interaction, file transfer, shell and process control, SOCKS proxying, service installation, and in-memory PE delivery.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.