Medusa Ransomware Actors

Also known as: Medusa Ransomware Actors

Medusa is a ransomware operation that reportedly launched in June 2021. In 2023, the group launched a website used to publicize alleged victims. The group appears to be independent of the similarly named “MedusaLocker” operation.[Bleeping Computer Medusa Ransomware March 12 2023]

According to data collected by the ransomwatch project and analyzed by Tidal, Medusa actors publicly claimed around 90 victims through September 2023, ranking it ninth out of the 50+ ransomware operations in the dataset. These victims come from a wide variety of industry sectors and localities.[GitHub ransomwatch]

Introduction

Medusa is a ransomware operation that reportedly launched in June 2021. In 2023, the group launched a website used to publicize alleged victims. The group appears to be independent of the similarly named “MedusaLocker” operation.[Bleeping Computer Medusa Ransomware March 12 2023] According to data collected by the ransomwatch project and analyzed by Tidal, Medusa actors publicly claimed around 90 victims through September 2023, ranking it ninth out of the 50+ ransomware operations in the dataset. These victims come from a wide variety of industry sectors and localities.[GitHub ransomwatch]

Activities and Tactics

Information pending cataloguing.

Notable Campaigns

Information pending cataloguing.

Tactics, Techniques, and Procedures (TTPs)

Information pending cataloguing.

Notable Indicators of Compromise (IOCs)

No curated IOCs are currently published for this actor. This section will be updated when stable, attributable indicators are available.

Malware and Tools

Information pending cataloguing.

Attribution and Evidence

Information pending cataloguing.

References

[1] [Bleeping Computer Medusa Ransomware March 12 2023 [2] ransomwatch project [3] [GitHub ransomwatch