Back to Ransomware Database
Ransomware Group
medusa
Medusa is a ransomware-as-a-service operation active since June 2021 that has targeted over 300 victims across critical infrastructure sectors including healthcare, education, legal, and manufacturing using double-extortion, with attacks surging 42% between 2023 and 2024 and a formal CISA advisory issued in early 2025.
Known victims517
Threat Level
CRITICAL
Tactics, Techniques & Procedures (TTPs)
CredentialTheft
- Mimikatz
DefenseEvasion
- EDRSandBlast
- KillAV
- ThrottleStop driver
DiscoveryEnum
- Advanced IP Scanner
- Navicat
- PDQ Inventory
- RoboCopy
- SoftPerfect NetScan
Exfiltration
- RClone
LOLBAS
- BITSAdmin
- Process Explorer
- PsExec
Networking
- Cloudflared
- FRP
- Ligolo
- PuTTY
- RevSocks
RMM-Tools
- AnyDesk
- Atera
- HCL BigFix
- N-Able
- PDQ Deploy
- +4 more
Check If You’re Affected
Search our database to see if your organization appears in medusa’s victim list.
Try it nowFree⌘K
Try
risk score · threat categories · sources · age · confidence — in one request