Medusa is a financially motivated ransomware operation active since 2021. Initially a closed operation, it transitioned to a ransomware-as-a-service model by early 2023, with developers supplying payloads and affiliates conducting intrusions. Also known as Medusa Blog and Medusa RaaS, the operation is distinct from MedusaLocker. Medusa has compromised more than 500 organizations, with extensive targeting of U.S. critical infrastructure. Frequently affected sectors include healthcare and public health, education, legal services, insurance, information technology, manufacturing, financial services, government services, and the defense industrial base. Healthcare has been a particularly frequent target. The operation purchases access through initial-access brokers, conducts credential phishing, and exploits exposed and unpatched public-facing applications, including rapidly weaponizing newly disclosed vulnerabilities. It uses credential dumping, native administrative utilities, PowerShell-based obfuscation, legitimate remote monitoring and management products, and remote desktop access for defense evasion, lateral movement, and post-compromise activity. Operators have also disabled security tooling, deleted shadow copies, stopped services, used remote-access tooling for persistence, and exfiltrated staged archives using commodity transfer utilities. Medusa employs double extortion: affiliates encrypt systems while threatening publication of stolen data through its leak site. It has also been reported to use additional pressure tactics consistent with triple extortion. Victims are commonly given a short period to begin negotiations, may be offered payment-related deadline extensions or discounts, and can be contacted directly to increase pressure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
48 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 malware families attributed to this actor across reporting.
4 additional families tracked in Mallory.
16 CVEs this actor has used in observed campaigns. 16 of them exploited in the wild.
Initial Access : Phishing [T1566], exploitation d’applications publiques [T1190] CVEs : CVE-2024-1709 (ScreenConnect), CVE-2023-48788 (Fortinet EMS), CVE-2025-10035, CVE-2026-1731
Initial Access : Phishing [T1566], exploitation d’applications publiques [T1190] CVEs : CVE-2024-1709 (ScreenConnect), CVE-2023-48788 (Fortinet EMS), CVE-2025-10035, CVE-2026-1731
Deux nouveaux CVE exploités : CVE-2025-10035 : désérialisation de données non fiables dans Fortra GoAnywhere (CWE-502) ... Weaponisation en moins de 24h après annonce publique d’un CVE, parfois jusqu’à une semaine avant la divulgation publique
CVE-2024-57727 (CVSS: 7.5): This flaw involves multiple path traversal vulnerabilities, permitting unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests.
CVE-2024-57728 (CVSS: 7.2): This vulnerability permits admin users to upload arbitrary files anywhere on the SimpleHelp file system by exploiting a crafted zip file, known as a zip slip. This could lead to arbitrary code execution on the host system in the context of the SimpleHelp server user.
11 more CVEs tied to this actor tracked in Mallory.
65 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware-as-a-service operation whose alleged member attempted to recruit an insider by offering a share of ransom proceeds for corporate access.
Ransomware-as-a-Service operations conducting breaches against hundreds of organizations, using initial access brokers, exploiting unpatched remote access vulnerabilities, compromising managed service providers, and employing double-extortion tactics.
Medusa Group appears only in the detection's annotations list.
Ransomware-as-a-service operation conducting double and sometimes triple extortion against critical infrastructure organizations, using initial access brokers, phishing, and exploitation of public-facing applications, followed by credential dumping, lateral movement, exfiltration, and encryption.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.