Skip to content

Medusa

Medusa is a financially motivated ransomware-as-a-service operation first identified in 2021 that has targeted hundreds of organizations across healthcare, education, legal, insurance, technology, manufacturing, and other critical sectors.

Profile source: Mallory opens in a new tab

Medusa

Family profile

Medusa is a financially motivated ransomware-as-a-service operation first identified in 2021 that has targeted hundreds of organizations across healthcare, education, legal, insurance, technology, manufacturing, and other critical sectors. It operates a double-extortion model in which operators or affiliates steal data before encrypting systems and then threaten public disclosure through a leak site if victims do not pay. Medusa began as a closed operation and later adopted an affiliate model, while core operators reportedly retained centralized control over negotiations.

Medusa commonly gains initial access through purchased footholds from initial access brokers, credential-phishing, and exploitation of vulnerable internet-facing services. Public reporting has linked the group to exploitation of ScreenConnect CVE-2024-1709, FortiClient EMS CVE-2023-48788, and SimpleHelp vulnerabilities including CVE-2024-57727 and CVE-2024-57728. In observed intrusions, operators used compromised remote-management infrastructure to hijack agents, redirect management traffic, and establish persistent access.

Post-compromise activity includes use of PowerShell, WMI, RDP, PsExec, Cobalt Strike, built-in Windows tooling, and commercial or legitimate remote-management software for execution, discovery, lateral movement, and staging. Medusa operators have also used network-scanning utilities and deployment tools to expand access across victim environments. Data theft commonly precedes encryption, with exfiltration frequently conducted using Rclone.

A notable feature of Medusa tradecraft is aggressive defense evasion. The operation has been associated with bring-your-own-vulnerable-driver techniques to disable or impair endpoint security products, including use of the ABYSSWORKER kernel driver in campaigns where a packed loader deployed the driver before ransomware execution. Reported behavior also includes terminating services, deleting shadow copies, and clearing PowerShell command history to hinder response and recovery.

On Windows systems, Medusa encrypts files and appends a characteristic extension, then drops a ransom note directing victims to negotiation channels. The operation is distinct from similarly named threats such as MedusaLocker, the Android banking trojan called Medusa, the Mythic agent named Medusa, and the open-source Linux rootkit of the same name.

Capabilities

  • Byovd
  • Defense Evasion
  • Exfiltration
  • Lateral Movement
  • Post Exploitation
  • Scanning

Operational record

24
Indicators
1
YARA rules
2
Ransom notes
9
Leak sites
0 available

Credential Theft

  • Mimikatz

Defense Evasion

  • EDRSandBlast
  • KillAV
  • ThrottleStop driver

Discovery Enum

  • Advanced IP Scanner
  • Navicat
  • PDQ Inventory
  • RoboCopy
  • SoftPerfect NetScan

Exfiltration

  • RClone

LOLBAS

  • BITSAdmin
  • Process Explorer
  • PsExec

Networking

  • Cloudflared
  • FRP
  • Ligolo
  • PuTTY
  • RevSocks

RMM Tools

  • AnyDesk
  • Atera
  • HCL BigFix
  • N-Able
  • PDQ Deploy
  • ScreenConnect
  • SimpleHelp
  • Splashtop
  • eHorus

Published indicators

Telegram

1 total
  • https://t.me/+yXOcSjVjI9tjM2E0

Md5

18 total
  • 983a20479a281a182d33b75c0945e447
  • 4fe99e5dc101170750d8ece6ea066155
  • dc344328208c3481587d0aab1005fcdd
  • 10911494fa52daee0279972f91fded01
  • 24ccd142ff83e8622f00f5443ea5cb2d
  • a6980e543efa40771ed1dcf84b29d732
  • a162a5c5ab72b3783215f52b9edc3680
  • 600371ebab1e29429f06a5b1909056e5
  • 0067679c7033139bcbb273840494b324
  • 602d720f1184d2ad739568cbf6403331

Tox

3 total
  • 4AE245548F2A225882951FB14E9BF87EE01A0C10AE159B99D1EA62620D91A372205227254A9F
  • 061AA6BDE8F6DE6C92F0D6E077359BF6911FCAF80030E82B3A3DB65E63C8011343D34F956FEC
  • AEA72DFCF492037A6D15755A74645C7D8E674E342BACA9F9070A3FB74117EC3143FD6E29BEAC

Email

2 total
  • medusa.support@onionmail.org
  • MedusaSupport@cock.li

Reported operators

Threat actors

13 named in public reporting
Mythic Likho

Название «Mythic» в имени кластера отражает использование Mythic C2 - открытого фреймворка для post-exploitation с множеством агентов (Apollo, Medusa, Athena).

Medusa Group

Since 6 February 2025, S-RM has responded to several incidents involving the ransomware group Medusa, where this group has exploited SimpleHelp vulnerabilities to gain initial access to victims’ infrastructure.

UNC3886

Researchers observed the group deploying Linux rootkits, including REPTILE and MEDUSA, after exploiting vCenter and ESXi vulnerabilities.

Lazarus

North Korea's Lazarus Group targets healthcare orgs with Medusa ransomware

Storm-1175

The Medusa ransomware activity, executed by the threat actor group Storm-1175, demonstrates a decisive shift toward exploit-centric, high-velocity intrusion models.

Blockade Spider

Essentially, OrBit is built from Medusa, an open-source LD_PRELOAD rootkit published on GitHub in December 2022.

Hastalamuerte

Hastalamuerte was an experienced affiliate who had previously worked with Embargo, LockBit, and Medusa before joining Qilin.

Andariel

Sample 1 ( gaze.exe ) is a fully functional Medusa ransomware binary whose XOR-encoded config (key 0x2E ) yields four Tor .onion C2 addresses, a victim-specific negotiation endpoint, and a kill list targeting 50+ enterprise security and backup services.

APT38

Sample 1 ( gaze.exe ) is a fully functional Medusa ransomware binary whose XOR-encoded config (key 0x2E ) yields four Tor .onion C2 addresses, a victim-specific negotiation endpoint, and a kill list targeting 50+ enterprise security and backup services.

Spearwing

Sample 1 ( gaze.exe ) is a fully functional Medusa ransomware binary whose XOR-encoded config (key 0x2E ) yields four Tor .onion C2 addresses, a victim-specific negotiation endpoint, and a kill list targeting 50+ enterprise security and backup services.

EncryptHub

Windows System Network Config Discovery Display DNS ... Medusa Ransomware, Windows Post-Exploitation, Prestige Ransomware, Water Gamayun

Contagious Interview

North Korean state-backed attackers are now using the Medusa ransomware... Medusa, which is operated by the Spearwing cybercrime group, was launched in 2023 and is run as a ransomware-as-a-service.

Pompilus

The North Korea-linked Lazarus Group (aka Diamond Sleet and Pompilus) has been observed using Medusa ransomware in an attack targeting an unnamed entity in the Middle East.

Exploited software

Vulnerabilities linked to Medusa

23 CVEs
CVE-2023-48788 SQL Injection Leading to RCE in Fortinet FortiClient EMS CVE-2024-1709 Authentication Bypass in ConnectWise ScreenConnect CVE-2024-57728 SimpleHelp Zip Slip Arbitrary File Upload Leading to RCE CVE-2024-57727 Unauthenticated Path Traversal in SimpleHelp CVE-2024-57726 SimpleHelp Missing Authorization Privilege Escalation CVE-2024-1708 ConnectWise ScreenConnect Path Traversal CVE-2024-37085 Authentication Bypass in VMware ESXi Active Directory Integration CVE-2023-21529 Microsoft Exchange Server Deserialization of Untrusted Data RCE CVE-2023-0669 Pre-authentication RCE in Fortra GoAnywhere MFT License Response Servlet CVE-2025-31324 Unauthenticated Arbitrary File Upload RCE in SAP NetWeaver Visual Composer Metadata Uploader CVE-2026-1731 Pre-auth OS Command Injection RCE in BeyondTrust Remote Support and Privileged Remote Access CVE-2025-10035 RCE in Fortra GoAnywhere MFT License Servlet CVE-2025-31161 CrushFTP AWS4-HMAC Authentication Bypass CVE-2024-27198 Authentication Bypass in JetBrains TeamCity On-Premises CVE-2026-23760 Authentication Bypass in SmarterTools SmarterMail Password Reset API CVE-2023-27351 Authentication Bypass in PaperCut NG/MF SecurityRequestFilter CVE-2024-27199 Relative Path Traversal in JetBrains TeamCity CVE-2025-52691 Unauthenticated Arbitrary File Upload in SmarterTools SmarterMail CVE-2024-21887 Command Injection in Ivanti Connect Secure and Ivanti Policy Secure CVE-2023-46805 Authentication Bypass in Ivanti Connect Secure and Policy Secure Web Component CVE-2023-27350 PaperCut MF/NG Authentication Bypass and RCE CVE-2022-41082 ProxyNotShell RCE in Microsoft Exchange Server PowerShell CVE-2022-41080 OWASSRF in Microsoft Exchange Server

MITRE ATT&CK

Medusa in ATT&CK

126 distinct techniques

Techniques

126 techniques
T1574 Hijack Execution Flow T1649 Steal or Forge Authentication Certificates T1560 Archive Collected Data T1003 OS Credential Dumping T1027 Obfuscated Files or Information T1213 Data from Information Repositories T1059.001 PowerShell T1547.001 Registry Run Keys / Startup Folder T1071.001 Web Protocols T1486 Data Encrypted for Impact T1490 Inhibit System Recovery T1133 External Remote Services T1489 Service Stop T1566 Phishing T1110 Brute Force T1562.001 Disable or Modify Tools T1574.006 Dynamic Linker Hijacking T1106 Native API T1556.003 Pluggable Authentication Modules T1564 Hide Artifacts T1014 Rootkit T1190 Exploit Public-Facing Application T1110.003 Password Spraying T1567 Exfiltration Over Web Service T1110.001 Password Guessing T1070 Indicator Removal T1564.009 Resource Forking T1021.004 SSH T1057 Process Discovery T1556 Modify Authentication Process T1059.003 Windows Command Shell T1056.004 Credential API Hooking T1564.001 Hidden Files and Directories T1622 Debugger Evasion T1136 Create Account T1082 System Information Discovery T1070.004 File Deletion T1140 Deobfuscate/Decode Files or Information T1547 Boot or Logon Autostart Execution T1562 Impair Defenses T1036 Masquerading T1546.008 Accessibility Features T1568 Dynamic Resolution T1056.001 Keylogging T1113 Screen Capture T1040 Network Sniffing T1006 Direct Volume Access T1078 Valid Accounts T1203 Exploitation for Client Execution T1210 Exploitation of Remote Services T1537 Transfer Data to Cloud Account T1041 Exfiltration Over C2 Channel T1021.001 Remote Desktop Protocol T1548.002 Bypass User Account Control T1135 Network Share Discovery T1497 Virtualization/Sandbox Evasion T1112 Modify Registry T1570 Lateral Tool Transfer T1484.001 Group Policy Modification T1505.003 Web Shell T1567.002 Exfiltration to Cloud Storage T1562.004 Disable or Modify System Firewall T1021 Remote Services T1219 Remote Access Tools T1589 Gather Victim Identity Information T1021.002 SMB/Windows Admin Shares T1595 Active Scanning T1543.003 Windows Service T1564.003 Hidden Window T1218.007 Msiexec T1007 System Service Discovery T1046 Network Service Discovery T1098.004 SSH Authorized Keys T1569.002 Service Execution T1047 Windows Management Instrumentation T1053 Scheduled Task/Job T1657 Financial Theft T1588.001 Malware T1018 Remote System Discovery T1016 System Network Configuration Discovery T1485 Data Destruction T1020 Automated Exfiltration T1518.002 Backup Software Discovery T1679 Selective Exclusion T1124 System Time Discovery T1518.001 Security Software Discovery T1027.013 Encrypted/Encoded File T1680 Local Storage Discovery T1083 File and Directory Discovery T1563.001 SSH Hijacking T1559 Inter-Process Communication T1071 Application Layer Protocol T1003.003 NTDS T1005 Data from Local System T1555.003 Credentials from Web Browsers T1105 Ingress Tool Transfer T1090 Proxy T1059 Command and Scripting Interpreter T1072 Software Deployment Tools T1559.001 Inter-Process Communication: Component Object Model T1136.002 Create Account: Domain Account T1027.002 Obfuscated Files or Information: Software Packing T1027.010 Obfuscated Files or Information: Command Obfuscation T1070.003 Indicator Removal: Clear Command History T1218.014 System Binary Proxy Execution: MMC T1562.009 Safe Mode Boot T1003.001 OS Credential Dumping: LSASS Memory T1033 System Owner/User Discovery T1069.002 Permission Groups Discovery: Domain Groups T1087.001 Account Discovery: Local Account T1652 Device Driver Discovery T1045 Exfiltration Over C2 Channel T1048 Exfiltration Over Alternative Protocol T1090.003 Proxy: Multi-hop Proxy T1573.002 Encrypted Channel: Asymmetric Cryptography T1529 System Shutdown/Reboot T1583.006 Acquire Infrastructure: Web Services T1585.001 Establish Accounts: Social Media Accounts T1585.002 Establish Accounts: Email Accounts T1588.002 Obtain Capabilities: Tool T1608.002 Stage Capabilities: Upload Tool T1650 Acquire Access T1553.002 Subvert Trust Controls: Code Signing T1685 Disable or Modify Tools T1686 Disable or Modify System Firewall T1690 Prevent Command History Logging

Reporting

Research mentioning Medusa

Jul 15
Gurucul Threat Research

How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist | Community Portal | Gurucul

Attackers compromised the Artlist WordPress subdomain new-blog.artlist[.]io and used it to deliver a sophisticated ClickFix malware campaign that presented visitors with a fake CAPTCHA and tricked them into running PowerShell. The injected JavaScript used an EtherHiding technique, querying a Polygon smart contract to dynamically retrieve the next-stage host auth-code-check[.]info, then downloaded a multi-stage infection chain from the attacker-controlled backend. Researchers traced the intrusion to WordPress credentials stolen from an Israeli freelance developer whose machine had been infected by an infostealer after downloading a pirated copy of Adobe Acrobat Pro DC in 2023. The payload chain reportedly used a password-protected archive, a signed StruSoft/FEM-Design updater, and DLL side-loading to decode shellcode and load a final native RAT that supported encrypted and Tor-backed C2, browser credential theft, keylogging, clipboard and screen access, hidden desktop interaction, file transfer, shell and process control, SOCKS proxying, service installation, and in-memory PE delivery.

Jul 14
Trojan Killer News

Artlist ClickFix Page Dropped a Native Windows RAT

Jul 14
Infostealers Com Infostealers

How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist | InfoStealers

Jul 14
Malware News

How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist - Malware Analysis - Malware Analysis, News and Indicators

Jul 14
Gurucul Threat Research

ClickFix: Exploiting Compromised WordPress Sites with a Polygon-Based C2 Infrastructure | Community Portal | Gurucul

Jul 14
Derp Ca

From EtherHiding to a native RAT: ClickFix on new-blog.artlist[.]io | Derp

Jul 14
Reddit Netsec

How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist : r/netsec

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.