Medusa has expanded into a global ransomware-as-a-service operation combining data theft, Windows encryption, and public pressure on victims. First observed in 2021 and distinct from MedusaLocker and Medusa Stealer, the operation accelerated in 2023, targeting organizations across multiple industries, particularly in the United States. Bitdefender reported 145 victims in 2023, while later reporting cited more than 500 cumulative victims; its projection of over 200 victims for 2024 was a forecast, not a confirmed total. Medusa uses Tor negotiation portals, leak-site countdowns, and Telegram publicity, with reported payment options to delay disclosure, purchase stolen information, or request deletion. Reports link its publicity operations to OSINT Without Borders, although ownership remains unconfirmed. Reported disruptions—including Dark Atlas removing victim information from a cloud account in 2024 and a subsequent U.S. Justice Department seizure of the associated OSINTCORP website—did not end Medusa’s operations.
Affiliates reportedly enter networks through phishing, stolen credentials, exposed infrastructure, and vulnerabilities including FortiClient EMS CVE-2023-48788, Citrix Bleed CVE-2023-4966, and ConnectWise ScreenConnect CVE-2024-1709. Attack chains involve credential theft, remote-management tools, lateral movement, exfiltration, and disabling security and backup services, including through vulnerable drivers. A September 2026 intelligence brief cautions that its broader 19-CVE inventory is not a confirmed exploitation list. Defensive priorities are rapid patching of internet-facing systems, phishing-resistant MFA, reduced remote-access exposure, monitoring for credential theft and exfiltration, isolated backups, and rehearsed incident response. Restoring backups addresses availability, but does not remove the confidentiality or extortion risks posed by stolen data.

See which actors are running it and whether you're in range.
14 events from the most recent confirmed update back to the earliest known activity.
Medusa introduced four additional onion domains on March 21, 2024, reportedly to address availability problems affecting its data-leak infrastructure.
The Raven File dates a redesign of Medusa's data-leak website to February 28, 2024.
In summer 2024, Dark Atlas reportedly obtained an exposed put.io authentication token from a configuration file and accessed Medusa's cloud account. It then began removing victim information.
The Raven File identifies June 2023 as a period of heightened Medusa ransomware activity.
The Raven File traced the Medusa onion address beginning xfv4jzck to February 2023. That address remained accessible during a later observation when other previously discussed sites were unavailable.
Bitdefender recorded 145 Medusa victims during 2023, documenting the operation's scale during that year.
Medusa reportedly expanded its global operations in early 2023, following its transition toward ransomware-as-a-service.
Medusa partnered with the Information Support Telegram channel to distribute stolen victim data and increase its visibility. The Raven File describes this as a publishing partnership rather than direct Medusa ownership of OSINTCORP.
A November 2022 announcement attributed to Robert introduced osintcorp.net and associated social channels through the shared Telegram channel. Medusa-related posts appeared in the following weeks.
Medusa reportedly began transitioning toward a ransomware-as-a-service model in late 2022, allowing affiliates to conduct attacks under a profit-sharing arrangement.
The Information Support Telegram channel, also known as OSINT_without_borders, was created on July 30, 2021. It later became a distribution channel for Medusa victim leaks.
Medusa emerged as a closed-source ransomware operation in June 2021. It is distinct from the MedusaLocker ransomware family.
The Raven File reports that OSINTCORP's clear-web website remained active until April 2025 and was subsequently seized by the U.S. Department of Justice. Medusa reportedly continued infecting victims after the seizure.
A subsequent Medusa website redesign introduced a dedicated data-leak directory at the onion address beginning 7aqabivk. The source does not date this redesign.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 51 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
blog.hunterstrategy.net
Open sourcetheravenfile.com
Open sourcebitdefender.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.