Introduction
Medusa Group has been active since at least 2021 and was initially operated as a closed ransomware group before evolving into a Ransomware-as-a-Service (RaaS) operation. Some reporting indicates that certain attacks may still be conducted directly by the ransomware’s core developers. Public sources have also referred to the group as “Spearwing” or “Medusa Actors.” CISA Medusa Group Medusa Ransomware March 2025 Broadcom Medusa Ransomware Medusa Group March 2025 Medusa Group employs living-off-the-land techniques, frequently leveraging publicly available tools and common remote management software to conduct operations. The group engages in double extortion tactics, exfiltrating data prior to encryption and threatening to publish stolen information if ransom demands are not met. Security Scorecard Medusa Ransomware January 2024 For initial access, Medusa Group has exploited publicly known vulnerabilities, conducted phishing campaigns, and used credentials or access purchased from Initial Access Brokers (IABs). The group is opportunistic and has targeted a wide range of sectors globally. Intel471 Medusa Ransomware May 2025
Activities and Tactics
Information pending cataloguing.
Notable Campaigns
Information pending cataloguing.
Tactics, Techniques, and Procedures (TTPs)
- T1490 Inhibit System Recovery
- T1047 Windows Management Instrumentation
- T1570 Lateral Tool Transfer
- T1543.003 Windows Service
- T1489 Service Stop
- T1106 Native API
- T1583.006 Web Services
- T1608.002 Upload Tool
- T1027.010 Command Obfuscation
- T1083 File and Directory Discovery
- T1112 Modify Registry
- T1588.002 Tool
- T1087.001 Local Account
- T1585.001 Social Media Accounts
- T1567.002 Exfiltration to Cloud Storage
- T1070.003 Clear Command History
- T1650 Acquire Access
- T1071.001 Web Protocols
- T1686 Disable or Modify System Firewall
- T1564.003 Hidden Window
- T1135 Network Share Discovery
- T1090.003 Multi-hop Proxy
- T1190 Exploit Public-Facing Application
- T1218.014 MMC
- T1585.002 Email Accounts
- T1078 Valid Accounts
- T1105 Ingress Tool Transfer
- T1057 Process Discovery
- T1559.001 Component Object Model
- T1219 Remote Access Tools
- T1003.003 NTDS
- T1018 Remote System Discovery
- T1569.002 Service Execution
- T1003.001 LSASS Memory
- T1573.002 Asymmetric Cryptography
- T1486 Data Encrypted for Impact
- T1059.001 PowerShell
- T1136.002 Domain Account
- T1657 Financial Theft
- T1652 Device Driver Discovery
- T1690 Prevent Command History Logging
- T1027.002 Software Packing
- T1070.004 File Deletion
- T1059.003 Windows Command Shell
- T1069.002 Domain Groups
- T1553.002 Code Signing
- T1505.003 Web Shell
- T1529 System Shutdown/Reboot
- T1518.001 Security Software Discovery
- T1016 System Network Configuration Discovery
- T1685 Disable or Modify Tools
- T1046 Network Service Discovery
- T1033 System Owner/User Discovery
- T1082 System Information Discovery
- T1021.001 Remote Desktop Protocol
- T1072 Software Deployment Tools
- T1548.002 Bypass User Account Control
ATT&CK technique IDs (denormalized)
- T1003.001
- T1003.003
- T1016
- T1018
- T1021.001
- T1027.002
- T1027.010
- T1033
- T1046
- T1047
- T1057
- T1059.001
- T1059.003
- T1069.002
- T1070.003
- T1070.004
- T1071.001
- T1072
- T1078
- T1082
- T1083
- T1087.001
- T1090.003
- T1105
- T1106
- T1112
- T1135
- T1136.002
- T1190
- T1218.014
- T1219
- T1486
- T1489
- T1490
- T1505.003
- T1518.001
- T1529
- T1543.003
- T1548.002
- T1553.002
- T1559.001
- T1564.003
- T1567.002
- T1569.002
- T1570
- T1573.002
- T1583.006
- T1585.001
- T1585.002
- T1588.002
- T1608.002
- T1650
- T1652
- T1657
- T1685
- T1686
- T1690
Notable Indicators of Compromise (IOCs)
No curated IOCs are currently published for this actor. This section will be updated when stable, attributable indicators are available.
Malware and Tools
MITRE ATT&CK Software
- certutil (S0160) — tool
- Rclone (S1040) — tool
- Medusa Ransomware (S1244) — malware
- Mimikatz (S0002) — tool
- PsExec (S0029) — tool
Attribution and Evidence
Information pending cataloguing.
References
[1] mitre-attack [2] CISA Medusa Group Medusa Ransomware March 2025 Cybersecurity and Infrastructure Security Agency. (2025, March 12). AA25-071A #StopRansomware: Medusa Ransomware. Retrieved October 15, 2025. [3] Intel471 Medusa Ransomware May 2025 Intel471. (2025, May 14). Threat hunting case study: Medusa ransomware. Retrieved October 15, 2025. [4] Broadcom Medusa Ransomware Medusa Group March 2025 Threat Hunter Team Symantec and Carbon Black. (2025, March 6). Medusa Ransomware Activity Continues to Increase. Retrieved October 15, 2025. [5] Security Scorecard Medusa Ransomware January 2024 Vlad Pasca. (2024, January 1). A Deep Dive into Medusa Ransomware. Retrieved October 15, 2025.