Medusa ransomware is a ransomware-as-a-service operation first identified in June 2021. Initially operated as a closed service, it had adopted an affiliate model by early 2023. It uses double extortion: affiliates steal data, encrypt victim systems, and threaten public disclosure if payment demands are not met. Medusa has affected more than 500 organizations across critical-infrastructure and commercial sectors, notably healthcare, education, legal services, insurance, technology, manufacturing, financial services, government, and the defense industrial base.
Medusa affiliates obtain access through phishing, purchased access from initial-access brokers, and exploitation of unpatched internet-facing applications, including ScreenConnect, Fortinet EMS, Fortra GoAnywhere, and BeyondTrust vulnerabilities. Operators have been observed rapidly weaponizing publicly disclosed vulnerabilities. Post-compromise activity includes credential dumping, use of PowerShell and other living-off-the-land techniques, deployment or abuse of legitimate remote-monitoring and remote-access tools, lateral movement through RDP and other administrative mechanisms, disabling security products, deleting shadow copies, archiving and exfiltrating data, and encrypting systems. The operation has been associated with financially motivated affiliates, including Storm-1175, and reporting has also documented Medusa deployment by Lazarus against U.S. healthcare and nonprofit targets. Medusa ransomware is distinct from the unrelated Medusa Linux rootkit, MedusaLocker ransomware, and Medusa Android banking trojan.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
20 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Initial Access : Phishing [T1566], exploitation d’applications publiques [T1190] CVEs : CVE-2024-1709 (ScreenConnect), CVE-2023-48788 (Fortinet EMS), CVE-2025-10035, CVE-2026-1731 | Medusa est une opération ransomware-as-a-service (RaaS) active depuis juin 2021, ayant impacté plus de 500 organisations d’infrastructure critique...
Deux nouveaux CVE exploités : ... CVE-2026-1731 : injection de commandes OS dans BeyondTrust (CWE-78) ... Weaponisation en moins de 24h après annonce publique d’un CVE, parfois jusqu’à une semaine avant la divulgation publique | Medusa est une opération ransomware-as-a-service (RaaS) active depuis juin 2021, ayant impacté plus de 500 organisations d’infrastructure critique...
Initial Access : Phishing [T1566], exploitation d’applications publiques [T1190] CVEs : CVE-2024-1709 (ScreenConnect), CVE-2023-48788 (Fortinet EMS), CVE-2025-10035, CVE-2026-1731 | Medusa est une opération ransomware-as-a-service (RaaS) active depuis juin 2021, ayant impacté plus de 500 organisations d’infrastructure critique...
Deux nouveaux CVE exploités : CVE-2025-10035 : désérialisation de données non fiables dans Fortra GoAnywhere (CWE-502) ... Weaponisation en moins de 24h après annonce publique d’un CVE, parfois jusqu’à une semaine avant la divulgation publique | Medusa est une opération ransomware-as-a-service (RaaS) active depuis juin 2021, ayant impacté plus de 500 organisations d’infrastructure critique...
In the recent campaign, according to Microsoft, the group may be exploiting CVE-2026-18577 - a flaw in the N-central, a remote monitoring and management (RMM) console used by various service providers to supervise client endpoints. The flaw allows threat actors “unauthenticated, ‘god-mode’ access,” warned cybersecurity firm Huntress.
Storm-1175 is the name assigned to a China-based threat actor with a history of deploying Medusa ransomware after exploiting security flaws in Mirth Connect (CVE-2023-37679, CVE-2023-43208). | The use of StormEncryptor marks a shift from the adversary's previous use of Medusa ransomware... Storm-1175 is the name assigned to a China-based threat actor with a history of deploying Medusa ransomware after exploiting security flaws...
Storm-1175 is the name assigned to a China-based threat actor with a history of deploying Medusa ransomware after exploiting security flaws in JetBrains TeamCity (CVE-2024-27198, CVE-2024-27199). | The use of StormEncryptor marks a shift from the adversary's previous use of Medusa ransomware... Storm-1175 is the name assigned to a China-based threat actor with a history of deploying Medusa ransomware after exploiting security flaws...
Storm-1175 is the name assigned to a China-based threat actor with a history of deploying Medusa ransomware after exploiting security flaws in ConnectWise ScreenConnect (CVE-2024-1709, CVE-2024-1708). | The use of StormEncryptor marks a shift from the adversary's previous use of Medusa ransomware... Storm-1175 is the name assigned to a China-based threat actor with a history of deploying Medusa ransomware after exploiting security flaws...
Storm-1175 is the name assigned to a China-based threat actor with a history of deploying Medusa ransomware after exploiting security flaws in JetBrains TeamCity (CVE-2024-27198, CVE-2024-27199). | The use of StormEncryptor marks a shift from the adversary's previous use of Medusa ransomware... Storm-1175 is the name assigned to a China-based threat actor with a history of deploying Medusa ransomware after exploiting security flaws...
Storm-1175 is the name assigned to a China-based threat actor with a history of deploying Medusa ransomware after exploiting security flaws in Mirth Connect (CVE-2023-37679, CVE-2023-43208). | The use of StormEncryptor marks a shift from the adversary's previous use of Medusa ransomware... Storm-1175 is the name assigned to a China-based threat actor with a history of deploying Medusa ransomware after exploiting security flaws...
CVE-2024-57728 (CVSS: 7.2): This vulnerability permits admin users to upload arbitrary files anywhere on the SimpleHelp file system by exploiting a crafted zip file, known as a zip slip. This could lead to arbitrary code execution on the host system in the context of the SimpleHelp server user. | Since 6 February 2025, S-RM has responded to several incidents involving the ransomware group Medusa, where this group has exploited SimpleHelp vulnerabilities to gain initial access to victims’ infrastructure.
CVE-2024-57727 (CVSS: 7.5): This flaw involves multiple path traversal vulnerabilities, permitting unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. | Since 6 February 2025, S-RM has responded to several incidents involving the ransomware group Medusa, where this group has exploited SimpleHelp vulnerabilities to gain initial access to victims’ infrastructure.
In the first quarter of 2025, Medusa ransomware operators launched a wave of coordinated attacks against UK organisations through compromised MSPs. | The campaigns, uncovered in early 2025, leveraged a trio of flaws—CVE-2024-57726, CVE-2024-57727, and CVE-2024-57728—to pivot from compromised RMM servers into victim networks with “minimal friction.”
This method was observed in high-tempo operations linked to Medusa affiliates (Storm-1175) and has been adopted by multiple groups deploying Akira and Black Basta payloads.
...the Microsoft Exchange Server deserialization of untrusted data bug, tracked as CVE-2023-21529, was included to the CISA list after being leveraged by Chinese financially motivated threat operation Storm-1175 to spread the Medusa ransomware. | the Microsoft Exchange Server deserialization of untrusted data bug, tracked as CVE-2023-21529, was included to the CISA list after being leveraged by Chinese financially motivated threat operation Storm-1175 to spread the Medusa ransomware.
The flaw in question is CVE-2023-0669, an SQL injection vulnerability that allows remote code execution without authentication. Discovered in February 2023, Fortra released an immediate patch, but attackers continue to exploit it months later. Medusa, an emerging ransomware-as-a-service (RaaS) group... | Medusa, an emerging ransomware-as-a-service (RaaS) group, has been targeting vulnerable Fortra's GoAnywhere MFT systems... Medusa scans the internet for exposed GoAnywhere servers, injecting malicious payloads to encrypt and exfiltrate data.
A notorious group of hackers is currently causing major disruption globally by deploying the devastating Medusa ransomware. | This pace was clear during a recent attack on a SAP NetWeaver system (tracked as CVE-2025-31324). The flaw was announced on April 24, 2025, and by April 25, the group was already using it to launch Medusa ransomware operations.
Storm-1175 actors are running up-tempo campaigns to deliver Medusa ransomware... Attackers move quickly from vulnerability exploitation to data exfiltration and, finally, delivery of Medusa ransomware, often within a few days and, in some cases, within 24 hours. | Other notable flaws exploited by Storm-1175 include CVE-2025-31161, a critical authentication bypass vulnerability in CrushFTP's file transfer software that also sparked a public disclosure dispute last spring.
The most recent example is CVE-2026-23760, a critical authentication bypass vulnerability in SmarterMail that was exploited by various threat groups, including the China-linked Storm-2603. | Storm-1175 actors are running up-tempo campaigns to deliver Medusa ransomware... Attackers move quickly from vulnerability exploitation to data exfiltration and, finally, delivery of Medusa ransomware, often within a few days and, in some cases, within 24 hours.
A notorious group of hackers is currently causing major disruption globally by deploying the devastating Medusa ransomware.
13 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Medusa is a ransomware-as-a-service platform that has operated since June 2021 and targets critical infrastructure.
Medusa is a ransomware-as-a-service platform that has operated since June 2021 and targets critical infrastructure.
На скомпрометированных управляющих Linux-хостах злоумышленники разворачивали набор инструментов для длительного доступа к инфраструктуре жертв. В него входили руткиты Medusa и REPTILE.
Medusa Ransomware has the capability to detect security solutions for termination or deletion within the victim device using hard-coded lists of strings containing security product executables.
In recent months, the Lazarus Group and its related intrusion set Moonstone Sleet have also been attributed to attacks targeting South Korean and Middle East entities with Qilin and Medusa ransomware.
Название «Mythic» в имени кластера отражает использование Mythic C2 - открытого фреймворка для post-exploitation с множеством агентов (Apollo, Medusa, Athena).
25 distinct techniques documented for this family, organized by ATT&CK tactic.
threat actors rarely break down the front door when they can buy key access from Initial Access Brokers (IABs) ... implementing continuous credential monitoring to catch compromised logins before they are monetized on the dark web.
Ransomware operators increasingly treat internet-facing appliances, unmanaged devices, and edge infrastructure as their primary point of entry.
Cl0p's signature move is mass exploitation of enterprise software... exploiting zero-day vulnerabilities in widely used enterprise file-transfer and business software. Storm-1175 is also described as exploiting newly disclosed vulnerabilities in GoAnywhere MFT, SmarterMail, and Ivanti Connect Secure.
Medusa heavily leverages dual-use utilities (PowerShell, remote management tools) and stolen credentials rather than custom binaries.
Dynamic Linker Hijacking occurs when an attacker manipulates the linking process to redirect execution flow. This can involve altering the library search order through LD_PRELOAD, modifying configuration files like /etc/ld.so.conf, or tampering with cached library mappings in /etc/ld.so.cache.
threat actors rarely break down the front door when they can buy key access from Initial Access Brokers (IABs) ... implementing continuous credential monitoring to catch compromised logins before they are monetized on the dark web.
На скомпрометированных управляющих Linux-хостах злоумышленники разворачивали ... руткиты Medusa и REPTILE.
BridgeAgent... masqueraded as a Zabbix monitoring agent... disguised its process as /usr/bin/gnome-shell. Across the Linux management hosts, Fire Ant used binaries renamed and timestamped to impersonate the SentinelOne and Cybereason endpoint security agents.
BridgeAgent ... маскировал свой процесс под /usr/bin/gnome-shell. Некоторые бинарники злоумышленники переименовывали ... чтобы выдать файлы за легитимные агенты SentinelOne и Cybereason.
They also attempt to cover their tracks by deleting the PowerShell command line history.
Некоторые бинарники злоумышленники ... меняли их временные метки ... Также хакеры меняли временные метки файлов, чтобы затруднить расследование и восстановление хронологии атаки.
threat actors rarely break down the front door when they can buy key access from Initial Access Brokers (IABs) ... implementing continuous credential monitoring to catch compromised logins before they are monetized on the dark web.
Dynamic Linker Hijacking occurs when an attacker manipulates the linking process to redirect execution flow. This can involve altering the library search order through LD_PRELOAD, modifying configuration files like /etc/ld.so.conf, or tampering with cached library mappings in /etc/ld.so.cache.
BlackCat encrypts Windows, Linux, and VMware ESXi systems; Play uses intermittent encryption and has a Linux variant targeting VMware ESXi; INC encrypts Windows and Linux/ESXi systems.
The encrypted files have a .medusa file extension, which terminates all services and deletes shadow copies before dropping a ransom note to the victim.
124 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Double-extortion RaaS platform using a Tor leak site and countdown timers. It has targeted healthcare, education, legal, insurance, technology, and manufacturing organizations.
Ransomware-as-a-service operation whose alleged member attempted to recruit an insider by offering a share of a prospective ransom payment for corporate-system access.
A Linux rootkit used as part of a toolkit for persistent access on compromised Linux management hosts.
A rootkit-related component set used on Linux management systems alongside custom SSH backdoors. Artifacts include a hijacked shared object, a working directory, and startup scripting.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.