Medusa is a ransomware-as-a-service operation active since at least 2021. It is commonly tracked as Medusa, Medusa ransomware, Medusa Blog, and related affiliate or gang designations. The operation is financially motivated and uses double-extortion tactics, combining data theft with encryption and leak-site pressure. Medusa has targeted a broad range of organizations, including healthcare, industrial, and critical infrastructure entities. Reporting places it among the more frequently encountered ransomware actors in 2024–2025 incident response activity. Victimology is opportunistic and often driven by exposure of vulnerable public-facing services and remote management infrastructure rather than by a narrow regional focus. A defining characteristic of Medusa activity is aggressive exploitation of internet-exposed enterprise software for initial access. The group has been observed exploiting CVE-2023-48788 in FortiClient Enterprise Management Server and chaining CVE-2024-57727 with CVE-2024-57728 in SimpleHelp deployments to compromise management servers, obtain administrative access, and redirect managed agents under attacker control. In these intrusions, Medusa used the compromised remote-management layer to move laterally, establish persistence, exfiltrate data, and deploy ransomware. Medusa also abuses legitimate remote monitoring and management tools as part of its intrusion lifecycle. Observed tradecraft includes use of SimpleHelp and other remote access software for persistence and hands-on-keyboard operations. Post-compromise behavior has included credential theft, LSASS dumping, creation of local administrative accounts, lateral movement, data exfiltration, and staged ransomware deployment through enterprise administration tooling. The group’s defense-evasion tradecraft includes disabling or degrading endpoint security controls. Medusa-linked intrusions have featured use of EDR-killer tooling and bring-your-own-vulnerable-driver techniques, including commercial or shared tools seen across the ransomware ecosystem. Reporting also notes use of vulnerable or signed drivers to interfere with security products on victim systems. Technique reporting associated with Medusa includes PowerShell execution, exploitation for privilege escalation, Windows service creation or modification for persistence and installation, and proxying or anonymization for command and control. Like many mature ransomware affiliate ecosystems, Medusa appears to combine bespoke intrusion steps with commodity administrative tools and shared underground tooling. Known aliases include Medusa, Medusa ransomware, Medusa Blog, Medusa ransomware gang, Medusa ransomware group, Medusa affiliates, and related naming variants. Available reporting supports characterization of Medusa as a criminal ransomware enterprise rather than a nation-state actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
58 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 malware families attributed to this actor across reporting.
4 additional families tracked in Mallory.
15 CVEs this actor has used in observed campaigns. 15 of them exploited in the wild.
Medusa Group has also utilized ... CVE-2023-48788 in Fortinet EMS for initial access to victim environments.
Medusa Group has also utilized CVE-2024-1709 in ScreenConnect ... for initial access to victim environments.
CVE-2024-57727 (CVSS: 7.5): This flaw involves multiple path traversal vulnerabilities, permitting unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests.
CVE-2024-57728 (CVSS: 7.2): This vulnerability permits admin users to upload arbitrary files anywhere on the SimpleHelp file system by exploiting a crafted zip file, known as a zip slip. This could lead to arbitrary code execution on the host system in the context of the SimpleHelp server user.
The deserialization vulnerability, tracked as CVE-2025-10035, "allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection," Fortra said... CISA ... warning that it was being actively used in ransomware campaigns.
10 more CVEs tied to this actor tracked in Mallory.
65 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware group listed as capable of targeting World Cup-related organizations for extortion.
Referenced as a ransomware group whose affiliates allegedly overlapped with Gentlemen operators.
Referenced as a ransomware operation for which The Gentlemen founder was previously an affiliate.
Claimed responsibility for a ransomware attack against UK healthcare provider HCRG Care Group and provided data later reported by SuspectFile.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.