Medusa is a ransomware-as-a-service operation first identified in June 2021, distinct from both MedusaLocker and the unrelated open-source Linux rootkit named Medusa. It evolved from a closed operation to an affiliate-based model by at least early 2023. Medusa developers and affiliates use double extortion: they steal data, encrypt victim systems, and threaten public release of the stolen material if ransom demands are not met. Some activity has also been characterized as triple extortion.
Medusa commonly obtains initial access through phishing, stolen credentials and access brokers, and exploitation of newly disclosed internet-facing vulnerabilities, including CVE-2024-1709, CVE-2023-48788, CVE-2025-10035, and CVE-2026-1731. Operators have demonstrated rapid exploitation of public vulnerabilities. Post-compromise activity includes security-product discovery, credential dumping, Active Directory theft, PowerShell-based defense evasion, deletion of shadow copies, termination of security and backup services, use of legitimate remote-access and remote-management tools, lateral movement through RDP and other administrative mechanisms, data staging and archival, and exfiltration. The Windows encryptor uses AES-256 encryption and applies a Medusa-specific extension to encrypted files; Linux and ESXi environments have also been affected.
As of April 2026, Medusa actors had impacted more than 500 victims across critical-infrastructure and commercial sectors. Frequently affected sectors include healthcare and public health, defense industrial base, manufacturing, government, information technology, financial services, education, legal services, and insurance. Healthcare has been a particularly frequent target.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
20 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Initial Access : Phishing [T1566], exploitation d’applications publiques [T1190] CVEs : CVE-2024-1709 (ScreenConnect), CVE-2023-48788 (Fortinet EMS), CVE-2025-10035, CVE-2026-1731 | Medusa est une opération ransomware-as-a-service (RaaS) active depuis juin 2021, ayant impacté plus de 500 organisations d’infrastructure critique...
Deux nouveaux CVE exploités : ... CVE-2026-1731 : injection de commandes OS dans BeyondTrust (CWE-78) ... Weaponisation en moins de 24h après annonce publique d’un CVE, parfois jusqu’à une semaine avant la divulgation publique | Medusa est une opération ransomware-as-a-service (RaaS) active depuis juin 2021, ayant impacté plus de 500 organisations d’infrastructure critique...
Initial Access : Phishing [T1566], exploitation d’applications publiques [T1190] CVEs : CVE-2024-1709 (ScreenConnect), CVE-2023-48788 (Fortinet EMS), CVE-2025-10035, CVE-2026-1731 | Medusa est une opération ransomware-as-a-service (RaaS) active depuis juin 2021, ayant impacté plus de 500 organisations d’infrastructure critique...
Deux nouveaux CVE exploités : CVE-2025-10035 : désérialisation de données non fiables dans Fortra GoAnywhere (CWE-502) ... Weaponisation en moins de 24h après annonce publique d’un CVE, parfois jusqu’à une semaine avant la divulgation publique | Medusa est une opération ransomware-as-a-service (RaaS) active depuis juin 2021, ayant impacté plus de 500 organisations d’infrastructure critique...
In the recent campaign, according to Microsoft, the group may be exploiting CVE-2026-18577 - a flaw in the N-central, a remote monitoring and management (RMM) console used by various service providers to supervise client endpoints. The flaw allows threat actors “unauthenticated, ‘god-mode’ access,” warned cybersecurity firm Huntress.
Storm-1175 is the name assigned to a China-based threat actor with a history of deploying Medusa ransomware after exploiting security flaws in Mirth Connect (CVE-2023-37679, CVE-2023-43208). | The use of StormEncryptor marks a shift from the adversary's previous use of Medusa ransomware... Storm-1175 is the name assigned to a China-based threat actor with a history of deploying Medusa ransomware after exploiting security flaws...
Storm-1175 is the name assigned to a China-based threat actor with a history of deploying Medusa ransomware after exploiting security flaws in JetBrains TeamCity (CVE-2024-27198, CVE-2024-27199). | The use of StormEncryptor marks a shift from the adversary's previous use of Medusa ransomware... Storm-1175 is the name assigned to a China-based threat actor with a history of deploying Medusa ransomware after exploiting security flaws...
Storm-1175 is the name assigned to a China-based threat actor with a history of deploying Medusa ransomware after exploiting security flaws in ConnectWise ScreenConnect (CVE-2024-1709, CVE-2024-1708). | The use of StormEncryptor marks a shift from the adversary's previous use of Medusa ransomware... Storm-1175 is the name assigned to a China-based threat actor with a history of deploying Medusa ransomware after exploiting security flaws...
Storm-1175 is the name assigned to a China-based threat actor with a history of deploying Medusa ransomware after exploiting security flaws in JetBrains TeamCity (CVE-2024-27198, CVE-2024-27199). | The use of StormEncryptor marks a shift from the adversary's previous use of Medusa ransomware... Storm-1175 is the name assigned to a China-based threat actor with a history of deploying Medusa ransomware after exploiting security flaws...
Storm-1175 is the name assigned to a China-based threat actor with a history of deploying Medusa ransomware after exploiting security flaws in Mirth Connect (CVE-2023-37679, CVE-2023-43208). | The use of StormEncryptor marks a shift from the adversary's previous use of Medusa ransomware... Storm-1175 is the name assigned to a China-based threat actor with a history of deploying Medusa ransomware after exploiting security flaws...
CVE-2024-57728 (CVSS: 7.2): This vulnerability permits admin users to upload arbitrary files anywhere on the SimpleHelp file system by exploiting a crafted zip file, known as a zip slip. This could lead to arbitrary code execution on the host system in the context of the SimpleHelp server user. | Since 6 February 2025, S-RM has responded to several incidents involving the ransomware group Medusa, where this group has exploited SimpleHelp vulnerabilities to gain initial access to victims’ infrastructure.
CVE-2024-57727 (CVSS: 7.5): This flaw involves multiple path traversal vulnerabilities, permitting unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. | Since 6 February 2025, S-RM has responded to several incidents involving the ransomware group Medusa, where this group has exploited SimpleHelp vulnerabilities to gain initial access to victims’ infrastructure.
In the first quarter of 2025, Medusa ransomware operators launched a wave of coordinated attacks against UK organisations through compromised MSPs. | The campaigns, uncovered in early 2025, leveraged a trio of flaws—CVE-2024-57726, CVE-2024-57727, and CVE-2024-57728—to pivot from compromised RMM servers into victim networks with “minimal friction.”
This method was observed in high-tempo operations linked to Medusa affiliates (Storm-1175) and has been adopted by multiple groups deploying Akira and Black Basta payloads.
...the Microsoft Exchange Server deserialization of untrusted data bug, tracked as CVE-2023-21529, was included to the CISA list after being leveraged by Chinese financially motivated threat operation Storm-1175 to spread the Medusa ransomware. | the Microsoft Exchange Server deserialization of untrusted data bug, tracked as CVE-2023-21529, was included to the CISA list after being leveraged by Chinese financially motivated threat operation Storm-1175 to spread the Medusa ransomware.
The flaw in question is CVE-2023-0669, an SQL injection vulnerability that allows remote code execution without authentication. Discovered in February 2023, Fortra released an immediate patch, but attackers continue to exploit it months later. Medusa, an emerging ransomware-as-a-service (RaaS) group... | Medusa, an emerging ransomware-as-a-service (RaaS) group, has been targeting vulnerable Fortra's GoAnywhere MFT systems... Medusa scans the internet for exposed GoAnywhere servers, injecting malicious payloads to encrypt and exfiltrate data.
A notorious group of hackers is currently causing major disruption globally by deploying the devastating Medusa ransomware. | This pace was clear during a recent attack on a SAP NetWeaver system (tracked as CVE-2025-31324). The flaw was announced on April 24, 2025, and by April 25, the group was already using it to launch Medusa ransomware operations.
Storm-1175 actors are running up-tempo campaigns to deliver Medusa ransomware... Attackers move quickly from vulnerability exploitation to data exfiltration and, finally, delivery of Medusa ransomware, often within a few days and, in some cases, within 24 hours. | Other notable flaws exploited by Storm-1175 include CVE-2025-31161, a critical authentication bypass vulnerability in CrushFTP's file transfer software that also sparked a public disclosure dispute last spring.
The most recent example is CVE-2026-23760, a critical authentication bypass vulnerability in SmarterMail that was exploited by various threat groups, including the China-linked Storm-2603. | Storm-1175 actors are running up-tempo campaigns to deliver Medusa ransomware... Attackers move quickly from vulnerability exploitation to data exfiltration and, finally, delivery of Medusa ransomware, often within a few days and, in some cases, within 24 hours.
A notorious group of hackers is currently causing major disruption globally by deploying the devastating Medusa ransomware.
14 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
На скомпрометированных управляющих Linux-хостах злоумышленники разворачивали набор инструментов для длительного доступа к инфраструктуре жертв. В него входили руткиты Medusa и REPTILE.
It marks a departure from the Medusa ransomware previously used by the group... Storm-1175’s ransomware activity is similar to the Medusa ransomware campaigns previously attributed to the same hacking group.
Medusa Ransomware has the capability to detect security solutions for termination or deletion within the victim device using hard-coded lists of strings containing security product executables.
In recent months, the Lazarus Group and its related intrusion set Moonstone Sleet have also been attributed to attacks targeting South Korean and Middle East entities with Qilin and Medusa ransomware.
In recent months, the Lazarus Group and its related intrusion set Moonstone Sleet have also been attributed to attacks targeting South Korean and Middle East entities with Qilin and Medusa ransomware.
Название «Mythic» в имени кластера отражает использование Mythic C2 - открытого фреймворка для post-exploitation с множеством агентов (Apollo, Medusa, Athena).
24 distinct techniques documented for this family, organized by ATT&CK tactic.
threat actors rarely break down the front door when they can buy key access from Initial Access Brokers (IABs) ... implementing continuous credential monitoring to catch compromised logins before they are monetized on the dark web.
Ransomware operators increasingly treat internet-facing appliances, unmanaged devices, and edge infrastructure as their primary point of entry.
На скомпрометированных управляющих Linux-хостах злоумышленники разворачивали ... руткиты Medusa и REPTILE.
BridgeAgent... masqueraded as a Zabbix monitoring agent... disguised its process as /usr/bin/gnome-shell. Across the Linux management hosts, Fire Ant used binaries renamed and timestamped to impersonate the SentinelOne and Cybereason endpoint security agents.
BridgeAgent ... маскировал свой процесс под /usr/bin/gnome-shell. Некоторые бинарники злоумышленники переименовывали ... чтобы выдать файлы за легитимные агенты SentinelOne и Cybereason.
They also attempt to cover their tracks by deleting the PowerShell command line history.
Medusa developers and affiliates use a double-extortion model in which they encrypt victim data and threaten to publicly release exfiltrated data if a ransom does not get paid... once they're in, exfiltration moves just as fast.
We’ve seen a significant (>55%) rise in OT systems being held for ransom; it’s not about just stealing data, it’s holding critical systems for ransom.
The encrypted files have a .medusa file extension, which terminates all services and deletes shadow copies before dropping a ransom note to the victim.
124 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware-as-a-service operation whose alleged member attempted to recruit an insider by offering a share of a prospective ransom payment for corporate-system access.
A Linux rootkit used as part of a toolkit for persistent access on compromised Linux management hosts.
A rootkit-related component set used on Linux management systems alongside custom SSH backdoors. Artifacts include a hijacked shared object, a working directory, and startup scripting.
Open-source rootkit used by Fire Ant as part of a durable access layer on compromised Linux management hosts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.