Medusa is a ransomware-as-a-service (RaaS) operation, also referred to in the provided content as Storm-1175 and Spearwing, and described as one of the top 10 most active ransomware threat actors in 2025. The content notes it should not be confused with similarly named malware such as Medusa Botnet/Medusa Stealer. Some reporting places earliest sightings in June 2021, while other sources place the start of its RaaS operations in late 2022. As of January 2026, more than 500 organizations were reportedly victimized. Medusa is assessed in the content as likely operating from Russia or a Russia-aligned state based on Cyrillic usage, Russian-language forum activity, Russian criminal slang, and apparent avoidance of CIS targets.
Medusa is described as broadly and opportunistically targeting organizations across sectors, including healthcare, with impacted victims observed across EMEA, the Americas, and Asia-Pacific/Japan. Financial services and automotive are cited as the most impacted sectors, followed by healthcare and others. The operation uses triple extortion: file encryption, threats to leak stolen data, and additional coercion such as DDoS or contacting victims' customers.
Initial access is described as commonly obtained through collaboration with initial access brokers using phishing, credential stuffing, or brute-force attacks, as well as exploitation of vulnerable or misconfigured internet-facing systems. Reported exploited vulnerabilities include Fortra GoAnywhere MFT License Servlet CVE-2025-10035, SimpleHelp CVE-2024-57726, CVE-2024-57727, and CVE-2024-57728, ConnectWise ScreenConnect CVE-2024-1709, Microsoft Exchange ProxyShell CVE-2021-34473, and Fortinet Enterprise Management Servers CVE-2023-48788.
A key tradecraft theme in the content is abuse of legitimate remote monitoring and management and remote access tools, especially SimpleHelp. Medusa is reported to use SimpleHelp for command and control, persistence, lateral movement, tool delivery, data exfiltration, and ransomware execution, and attackers can modify SimpleHelp server configuration to redirect existing agents to attacker-controlled servers. Other abused tools mentioned include Atera, AnyDesk, ScreenConnect, eHorus, N-able, PDQ Deploy/Inventory, Splashtop, TeamViewer, NinjaOne, Navicat, and MeshAgent. The content also notes use of Rclone and Robocopy for staging and exfiltration, and BYOVD to disable security tools.
Medusa ransomware is identified by appending the .MEDUSA extension to encrypted files and dropping the ransom note !!!READ_ME_MEDUSA!!!.txt. Darktrace reported observing Medusa-related encryption activity across customers between December 2023 and November 2025. In a detailed Q4 2025 European incident, telemetry indicated lateral movement via RDP, NTLM/SMB, DCE_RPC, and PowerShell, followed by long-lived C2 to malicious SimpleHelp servers 31.220.45[.]120 and 213.183.63[.]41, exfiltration of about 70 GiB to erp.ranasons[.]com (143.110.243[.]154), and ransomware execution involving gaze.exe and !!!READ_ME_MEDUSA!!!.txt. Additional exfiltration infrastructure cited includes pruebas.pintacuario[.]mx (144.217.181[.]205), with traffic observed over ports 443, 445, and 80; the content also notes a mid-2024 compromise involving Ngrok-associated destinations using an SSH-2.0-rclone client.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
"Medusa ransomware should not be confused with other similarly named malware, such as ... the Medusa Botnet/Medusa Stealer..."
"Medusa ransomware should not be confused with other similarly named malware, such as ... the Medusa Botnet/Medusa Stealer..."
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.