Credential Theft
- Mimikatz
Medusa is a ransomware-as-a-service operation first identified in June 2021, distinct from both MedusaLocker and the unrelated open-source Linux rootkit named Medusa.
Profile source: Mallory opens in a new tabMedusa
Medusa is a ransomware-as-a-service operation first identified in June 2021, distinct from both MedusaLocker and the unrelated open-source Linux rootkit named Medusa. It evolved from a closed operation to an affiliate-based model by at least early 2023. Medusa developers and affiliates use double extortion: they steal data, encrypt victim systems, and threaten public release of the stolen material if ransom demands are not met. Some activity has also been characterized as triple extortion.
Medusa commonly obtains initial access through phishing, stolen credentials and access brokers, and exploitation of newly disclosed internet-facing vulnerabilities, including CVE-2024-1709, CVE-2023-48788, CVE-2025-10035, and CVE-2026-1731. Operators have demonstrated rapid exploitation of public vulnerabilities. Post-compromise activity includes security-product discovery, credential dumping, Active Directory theft, PowerShell-based defense evasion, deletion of shadow copies, termination of security and backup services, use of legitimate remote-access and remote-management tools, lateral movement through RDP and other administrative mechanisms, data staging and archival, and exfiltration. The Windows encryptor uses AES-256 encryption and applies a Medusa-specific extension to encrypted files; Linux and ESXi environments have also been affected.
As of April 2026, Medusa actors had impacted more than 500 victims across critical-infrastructure and commercial sectors. Frequently affected sectors include healthcare and public health, defense industrial base, manufacturing, government, information technology, financial services, education, legal services, and insurance. Healthcare has been a particularly frequent target.
https://t.me/+yXOcSjVjI9tjM2E0983a20479a281a182d33b75c0945e4474fe99e5dc101170750d8ece6ea066155dc344328208c3481587d0aab1005fcdd10911494fa52daee0279972f91fded0124ccd142ff83e8622f00f5443ea5cb2da6980e543efa40771ed1dcf84b29d732a162a5c5ab72b3783215f52b9edc3680600371ebab1e29429f06a5b1909056e50067679c7033139bcbb273840494b324602d720f1184d2ad739568cbf64033314AE245548F2A225882951FB14E9BF87EE01A0C10AE159B99D1EA62620D91A372205227254A9F061AA6BDE8F6DE6C92F0D6E077359BF6911FCAF80030E82B3A3DB65E63C8011343D34F956FECAEA72DFCF492037A6D15755A74645C7D8E674E342BACA9F9070A3FB74117EC3143FD6E29BEACmedusa.support@onionmail.orgMedusaSupport@cock.liReported operators
На скомпрометированных управляющих Linux-хостах злоумышленники разворачивали набор инструментов для длительного доступа к инфраструктуре жертв. В него входили руткиты Medusa и REPTILE.
It marks a departure from the Medusa ransomware previously used by the group... Storm-1175’s ransomware activity is similar to the Medusa ransomware campaigns previously attributed to the same hacking group.
Medusa Ransomware has the capability to detect security solutions for termination or deletion within the victim device using hard-coded lists of strings containing security product executables.
In recent months, the Lazarus Group and its related intrusion set Moonstone Sleet have also been attributed to attacks targeting South Korean and Middle East entities with Qilin and Medusa ransomware.
In recent months, the Lazarus Group and its related intrusion set Moonstone Sleet have also been attributed to attacks targeting South Korean and Middle East entities with Qilin and Medusa ransomware.
Название «Mythic» в имени кластера отражает использование Mythic C2 - открытого фреймворка для post-exploitation с множеством агентов (Apollo, Medusa, Athena).
Essentially, OrBit is built from Medusa, an open-source LD_PRELOAD rootkit published on GitHub in December 2022.
Hastalamuerte was an experienced affiliate who had previously worked with Embargo, LockBit, and Medusa before joining Qilin.
Sample 1 ( gaze.exe ) is a fully functional Medusa ransomware binary whose XOR-encoded config (key 0x2E ) yields four Tor .onion C2 addresses, a victim-specific negotiation endpoint, and a kill list targeting 50+ enterprise security and backup services.
Sample 1 ( gaze.exe ) is a fully functional Medusa ransomware binary whose XOR-encoded config (key 0x2E ) yields four Tor .onion C2 addresses, a victim-specific negotiation endpoint, and a kill list targeting 50+ enterprise security and backup services.
Sample 1 ( gaze.exe ) is a fully functional Medusa ransomware binary whose XOR-encoded config (key 0x2E ) yields four Tor .onion C2 addresses, a victim-specific negotiation endpoint, and a kill list targeting 50+ enterprise security and backup services.
Windows System Network Config Discovery Display DNS ... Medusa Ransomware, Windows Post-Exploitation, Prestige Ransomware, Water Gamayun
North Korean state-backed attackers are now using the Medusa ransomware... Medusa, which is operated by the Spearwing cybercrime group, was launched in 2023 and is run as a ransomware-as-a-service.
The North Korea-linked Lazarus Group (aka Diamond Sleet and Pompilus) has been observed using Medusa ransomware in an attack targeting an unnamed entity in the Middle East.
Exploited software
MITRE ATT&CK
Reporting
CISA, the FBI, and HHS issued an updated joint advisory warning that Medusa ransomware operators have compromised more than 500 organizations as of April 2026, with heavy targeting of critical infrastructure and especially healthcare and public health entities. The agencies said the group evolved from a closed operation into a ransomware-as-a-service model in 2023, using double extortion by stealing data before encrypting systems. Officials said Medusa actors can exploit newly disclosed vulnerabilities within 24 hours, and in some cases were observed abusing flaws up to a week before public disclosure. The advisory said Medusa gains access through initial access brokers, reportedly offering up to $1 million for exclusive access, and has exploited vulnerabilities including CVE-2024-1709, CVE-2023-48788, GoAnywhere MFT flaws, and CVE-2026-1731. Once inside, operators use living-off-the-land techniques, credential dumping, stolen or vulnerable drivers, and legitimate remote monitoring and management tools to disable security controls, move laterally, steal sensitive data, and encrypt networks. Authorities also described aggressive extortion tactics such as rapid-payment discounts and paid deadline extensions, while urging organizations to patch quickly, segment networks, enforce phishing-resistant MFA, maintain offline immutable backups, and monitor for unauthorized RMM activity.
The Clop ransomware operation has repeatedly targeted enterprise networks with intrusions that begin with phishing or exploitation of exposed systems, followed by manual lateral movement, credential theft, and domain-wide deployment. Reporting from ANSSI and AhnLab linked earlier campaigns to TA505, describing attacks in which operators used tools such as Cobalt Strike and Mimikatz, encrypted files with .Clop or .CIop extensions, and disrupted business operations at victims including E-Land Group, Software AG, and reportedly Indiabulls Group. Analysts also observed Clop using signed malware components, targeting Active Directory environments, stopping business-critical services before encryption, and in some cases preserving shadow copies depending on the variant. The group increasingly shifted from encryption-only attacks to double extortion and broader data-leak pressure tactics. Clop operators published stolen files on leak sites, demanded multimillion-dollar payments, contacted victims' customers directly to intensify pressure, and were tied to mass data-theft campaigns exploiting managed file transfer flaws such as CVE-2023-0669 in Fortra GoAnywhere MFT, which was linked to theft from about 130 companies. More recent victim listings attributed to Clop include organizations in the U.S., Canada, Peru, China, Taiwan, and Europe across technology, manufacturing, retail, and other sectors, underscoring the group's continued global focus on enterprise-scale ransomware and data-breach operations.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.