Medusa is a financially motivated ransomware-as-a-service operation active since at least 2021 that conducts double-extortion attacks against organizations across healthcare, education, manufacturing, legal, insurance, technology, and other critical sectors. It is distinct from MedusaLocker, the Android banking trojan also called Medusa, and the open-source Linux rootkit of the same name. Medusa has been linked to hundreds of victims and operates through an affiliate model while retaining centralized control over ransom negotiations.
Medusa commonly gains initial access through purchased footholds from initial access brokers, credential-phishing, and exploitation of vulnerable public-facing services. Reported intrusion vectors include FortiClient EMS CVE-2023-48788, ScreenConnect CVE-2024-1709, and SimpleHelp vulnerabilities including CVE-2024-57727 and CVE-2024-57728. After compromise, operators establish persistence with remote-management tooling, use PowerShell and WMI for execution, and leverage legitimate administrative utilities and remote access software during post-exploitation.
A notable feature of Medusa tradecraft is aggressive defense evasion through bring-your-own-vulnerable-driver techniques. In multiple intrusions, operators deployed the ABYSSWORKER malicious driver, often via a packed loader, to disable or impair endpoint detection and antivirus products. Medusa activity has also been associated with other EDR-killing tooling and with abuse of signed or vulnerable drivers to terminate protected security processes before ransomware deployment.
Within victim environments, Medusa performs reconnaissance, credential access, lateral movement, and data staging using a mix of built-in Windows tools and common offensive utilities. Observed activity includes use of RDP, PsExec, Cobalt Strike, network scanners, and remote-management platforms. The group exfiltrates sensitive data before encryption, commonly using Rclone, then encrypts files and appends a Medusa-specific extension. Operators typically terminate services and delete shadow copies to inhibit recovery, then deliver a ransom note and threaten publication of stolen data on a leak site if payment is not made. Some reporting indicates victims may be subjected to repeated extortion demands even after payment.
Medusa primarily targets Windows environments and is best characterized as a mature criminal ransomware ecosystem that combines opportunistic exploitation of exposed infrastructure, affiliate-driven intrusions, data theft, defense impairment, and extortion at scale.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
21 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
affiliates frequently buy footholds from initial access brokers, and gain entry through phishing for credentials and exploitation of unpatched internet-facing software — notably ScreenConnect (CVE-2024-1709) and Fortinet FortiClient EMS (CVE-2023-48788). | Medusa is a ransomware-as-a-service operation that has hit 300+ organisations across healthcare, education, manufacturing and other critical sectors. It buys its way in, disables endpoint defenses with a bring-your-own-vulnerable-driver attack, steals data, and then encrypts with the .medusa extension and a public leak blog.
affiliates frequently buy footholds from initial access brokers, and gain entry through phishing for credentials and exploitation of unpatched internet-facing software — notably ScreenConnect (CVE-2024-1709) and Fortinet FortiClient EMS (CVE-2023-48788). | Medusa is a ransomware-as-a-service operation that has hit 300+ organisations across healthcare, education, manufacturing and other critical sectors. It buys its way in, disables endpoint defenses with a bring-your-own-vulnerable-driver attack, steals data, and then encrypts with the .medusa extension and a public leak blog.
CVE-2024-57728 (CVSS: 7.2): This vulnerability permits admin users to upload arbitrary files anywhere on the SimpleHelp file system by exploiting a crafted zip file, known as a zip slip. This could lead to arbitrary code execution on the host system in the context of the SimpleHelp server user. | Since 6 February 2025, S-RM has responded to several incidents involving the ransomware group Medusa, where this group has exploited SimpleHelp vulnerabilities to gain initial access to victims’ infrastructure.
CVE-2024-57727 (CVSS: 7.5): This flaw involves multiple path traversal vulnerabilities, permitting unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. | Since 6 February 2025, S-RM has responded to several incidents involving the ransomware group Medusa, where this group has exploited SimpleHelp vulnerabilities to gain initial access to victims’ infrastructure.
In the first quarter of 2025, Medusa ransomware operators launched a wave of coordinated attacks against UK organisations through compromised MSPs. | The campaigns, uncovered in early 2025, leveraged a trio of flaws—CVE-2024-57726, CVE-2024-57727, and CVE-2024-57728—to pivot from compromised RMM servers into victim networks with “minimal friction.”
Earlier this month, Microsoft linked the exploitation of the flaws to a China-based threat actor it tracks as Storm-1175 in attacks deploying Medusa ransomware.
This method was observed in high-tempo operations linked to Medusa affiliates (Storm-1175) and has been adopted by multiple groups deploying Akira and Black Basta payloads.
...the Microsoft Exchange Server deserialization of untrusted data bug, tracked as CVE-2023-21529, was included to the CISA list after being leveraged by Chinese financially motivated threat operation Storm-1175 to spread the Medusa ransomware. | the Microsoft Exchange Server deserialization of untrusted data bug, tracked as CVE-2023-21529, was included to the CISA list after being leveraged by Chinese financially motivated threat operation Storm-1175 to spread the Medusa ransomware.
The flaw in question is CVE-2023-0669, an SQL injection vulnerability that allows remote code execution without authentication. Discovered in February 2023, Fortra released an immediate patch, but attackers continue to exploit it months later. Medusa, an emerging ransomware-as-a-service (RaaS) group... | Medusa, an emerging ransomware-as-a-service (RaaS) group, has been targeting vulnerable Fortra's GoAnywhere MFT systems... Medusa scans the internet for exposed GoAnywhere servers, injecting malicious payloads to encrypt and exfiltrate data.
A notorious group of hackers is currently causing major disruption globally by deploying the devastating Medusa ransomware. | This pace was clear during a recent attack on a SAP NetWeaver system (tracked as CVE-2025-31324). The flaw was announced on April 24, 2025, and by April 25, the group was already using it to launch Medusa ransomware operations.
Storm-1175 actors are running up-tempo campaigns to deliver Medusa ransomware... Attackers move quickly from vulnerability exploitation to data exfiltration and, finally, delivery of Medusa ransomware, often within a few days and, in some cases, within 24 hours. | Storm-1175 has rapidly exploited more than a dozen known vulnerabilities or N-days, the most recent of which is CVE-2026-1731, a critical remote code execution flaw in BeyondTrust Remote Support and older versions of the vendor's Privileged Remote Access (PRA). The vulnerability was initially disclosed Feb. 6 and quickly came under attack, with the Cybersecurity and Infrastructure Security Agency (CISA) adding it to the Known Exploited Vulnerabilities (KEV) catalog a week later.
Additionally, Storm-1175 weaponized CVE-2025-10035, a maximum-severity flaw in GoAnywhere's Managed File Transfer's (MFT) License Servlet. Microsoft noted that both CVEs were exploited about a week before public disclosure. | Storm-1175 actors are running up-tempo campaigns to deliver Medusa ransomware... Attackers move quickly from vulnerability exploitation to data exfiltration and, finally, delivery of Medusa ransomware, often within a few days and, in some cases, within 24 hours.
Storm-1175 actors are running up-tempo campaigns to deliver Medusa ransomware... Attackers move quickly from vulnerability exploitation to data exfiltration and, finally, delivery of Medusa ransomware, often within a few days and, in some cases, within 24 hours. | Other notable flaws exploited by Storm-1175 include CVE-2025-31161, a critical authentication bypass vulnerability in CrushFTP's file transfer software that also sparked a public disclosure dispute last spring.
Storm-1175 actors are running up-tempo campaigns to deliver Medusa ransomware... Attackers move quickly from vulnerability exploitation to data exfiltration and, finally, delivery of Medusa ransomware, often within a few days and, in some cases, within 24 hours. | Other notable flaws exploited by Storm-1175 include ... CVE-2024-27198, another critical authentication bypass flaw, this time affecting JetBrains' TeamCity and seeing mass exploitation just days after public disclosure in March 2024.
The most recent example is CVE-2026-23760, a critical authentication bypass vulnerability in SmarterMail that was exploited by various threat groups, including the China-linked Storm-2603. | Storm-1175 actors are running up-tempo campaigns to deliver Medusa ransomware... Attackers move quickly from vulnerability exploitation to data exfiltration and, finally, delivery of Medusa ransomware, often within a few days and, in some cases, within 24 hours.
A notorious group of hackers is currently causing major disruption globally by deploying the devastating Medusa ransomware.
Since 2023, Microsoft Threat Intelligence has observed exploitation of over 16 vulnerabilities, including: CVE-2024-27198 and CVE-2024-27199 (JetBrains TeamCity) | China-based actor Storm-1175 runs fast ransomware attacks, exploiting new flaws to breach systems and quickly deploy Medusa ransomware.
China-based actor Storm-1175 runs fast ransomware attacks, exploiting new flaws to breach systems and quickly deploy Medusa ransomware. | Since 2023, Microsoft Threat Intelligence has observed exploitation of over 16 vulnerabilities, including: CVE-2025-52691 and CVE-2026-23760 (SmarterMail)
China-based actor Storm-1175 runs fast ransomware attacks, exploiting new flaws to breach systems and quickly deploy Medusa ransomware. | Since 2023, Microsoft Threat Intelligence has observed exploitation of over 16 vulnerabilities, including: CVE-2023-46805 and CVE-2024-21887 (Ivanti Connect Secure and Policy Secure)
Since 2023, Microsoft Threat Intelligence has observed exploitation of over 16 vulnerabilities, including: CVE-2023-46805 and CVE-2024-21887 (Ivanti Connect Secure and Policy Secure) | China-based actor Storm-1175 runs fast ransomware attacks, exploiting new flaws to breach systems and quickly deploy Medusa ransomware.
Since 2023, Microsoft Threat Intelligence has observed exploitation of over 16 vulnerabilities, including: CVE-2023-27351 and CVE-2023-27350 (Papercut) | China-based actor Storm-1175 runs fast ransomware attacks, exploiting new flaws to breach systems and quickly deploy Medusa ransomware.
13 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Название «Mythic» в имени кластера отражает использование Mythic C2 - открытого фреймворка для post-exploitation с множеством агентов (Apollo, Medusa, Athena).
Since 6 February 2025, S-RM has responded to several incidents involving the ransomware group Medusa, where this group has exploited SimpleHelp vulnerabilities to gain initial access to victims’ infrastructure.
Researchers observed the group deploying Linux rootkits, including REPTILE and MEDUSA, after exploiting vCenter and ESXi vulnerabilities.
North Korea's Lazarus Group targets healthcare orgs with Medusa ransomware
The Medusa ransomware activity, executed by the threat actor group Storm-1175, demonstrates a decisive shift toward exploit-centric, high-velocity intrusion models.
Essentially, OrBit is built from Medusa, an open-source LD_PRELOAD rootkit published on GitHub in December 2022.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
Medusa Locker has been known to exploit Remote Desktop Protocol (RDP) vulnerabilities to gain access to a victim’s machine
Execution - PowerShell (T1059.001). Внутри архива LNK-файл, который через powershell.exe запускает base64-закодированный скрипт.
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.
Looking at ransomware brands in our dataset from 2020 to 2025, three brands (LockBit, Medusa, Phobos) and one technique (abuse of native BitLocker encryption) have persisted for the duration.
Dynamic Linker Hijacking occurs when an attacker manipulates the linking process to redirect execution flow. This can involve altering the library search order through LD_PRELOAD, modifying configuration files like /etc/ld.so.conf, or tampering with cached library mappings in /etc/ld.so.cache.
Medusa Locker has been known to exploit Remote Desktop Protocol (RDP) vulnerabilities to gain access to a victim’s machine
PAM Backdoor → Hook libpam authentication system calls for persisting with a hidden root user
возможный persistence через Registry Run Keys / Startup Folder (T1547.001) - типичный механизм Mythic-агентов.
Auth Logging → Hooks pam_prompt() , pam_vprompt and pam_syslog to log all successful authentications locally, or remotely via SSH to Medusa home directory
PAM provides the essential capability to centralize how secure authentication happens, its flexibility can be abused by attackers to establish persistence through malicious PAM modules. By introducing custom modules or modifying existing configurations, attackers can manipulate authentication flows to capture credentials, manipulate logging to evade detection, grant unauthorized access, or execute malicious code.
Researchers observed the group deploying Linux rootkits, including REPTILE and MEDUSA, after exploiting vCenter and ESXi vulnerabilities. The implants helped hide attacker activity, maintain persistence, and support credential theft across compromised systems.
... разработчики The Gentlemen систематически реверсят семплы Babuk, Qilin, LockBit 5.0 и Medusa, вытаскивая ... техники обфускации (T1027) ...
Along the way, the operators rotate XOR keys, shuffle install paths, swap backdoor credentials, add auditd-evasion hooks... | All other capabilities are identical: file I/O interception, stat hiding, PAM credential capture, TCP port hiding... LD_PRELOAD management, log suppression, and process hiding.
Sometimes that means hiding files or processes. Other times it means suppressing logs, concealing outbound connections, or masking remote access entirely.
File Hiding → Hooks 'stat' and 'readdir' to hide files and directories.
Process Hiding → Hooks rootkit can intercept the 'kill' function to prevent the user from terminating the rootkit process. By hiding itself from the system, the rootkit can remain undetected and achieve persistence on the system.
Dynamic Linker Hijacking occurs when an attacker manipulates the linking process to redirect execution flow. This can involve altering the library search order through LD_PRELOAD, modifying configuration files like /etc/ld.so.conf, or tampering with cached library mappings in /etc/ld.so.cache.
Auth Logging → Hooks pam_prompt() , pam_vprompt and pam_syslog to log all successful authentications locally, or remotely via SSH to Medusa home directory
PAM provides the essential capability to centralize how secure authentication happens, its flexibility can be abused by attackers to establish persistence through malicious PAM modules. By introducing custom modules or modifying existing configurations, attackers can manipulate authentication flows to capture credentials, manipulate logging to evade detection, grant unauthorized access, or execute malicious code.
Auth Logging → Hooks pam_prompt() , pam_vprompt and pam_syslog to log all successful authentications locally, or remotely via SSH to Medusa home directory
Password attacks — guessing or cracking the credentials themselves ... Brute force — systematically trying every possible characters combination.
It’s designed to efficiently test combinations of usernames and passwords across a wide range of services and protocols.
Targeting Multiple Hosts medusa -H hosts.txt -u admin -P passwords.txt -M ssh -t 10
Auth Logging → Hooks pam_prompt() , pam_vprompt and pam_syslog to log all successful authentications locally, or remotely via SSH to Medusa home directory
PAM provides the essential capability to centralize how secure authentication happens, its flexibility can be abused by attackers to establish persistence through malicious PAM modules. By introducing custom modules or modifying existing configurations, attackers can manipulate authentication flows to capture credentials, manipulate logging to evade detection, grant unauthorized access, or execute malicious code.
The content repeatedly describes malware and threat actors obtaining lists of running processes, using utilities such as tasklist, ps, WMI, Get-Process, CreateToolhelp32Snapshot, EnumProcesses, and similar APIs/commands to enumerate active processes on victim systems.
The content repeatedly describes malware and threat actors collecting host details such as OS version, hostname, architecture, CPU, memory, BIOS, domain, language, and other configuration data; e.g., "APT41 uses multiple built-in commands such as systeminfo and net config Workstation to enumerate victim system basic configuration information."
96 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
186 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Double-extortion ransomware-as-a-service that gains access via bought footholds, phishing, and exploitation of internet-facing applications; disables EDR using the signed ABYSSWORKER driver in a BYOVD attack; exfiltrates data with tools such as Rclone; deletes shadow copies; encrypts files with the .medusa extension; and pressures victims via a leak blog, with reported re-extortion in some cases.
Агент фреймворка Mythic C2 для post-exploitation, упомянутый как часть инструментария, связанного с Mythic Likho.
Medusa4
A named crypto drainer active in 2024, used to steal cryptocurrency through phishing infrastructure and malicious wallet interactions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.