Skip to main content
Back to Ransomware Database
Ransomware Group

medusa

Medusa is a ransomware-as-a-service operation active since June 2021 that has targeted over 300 victims across critical infrastructure sectors including healthcare, education, legal, and manufacturing using double-extortion, with attacks surging 42% between 2023 and 2024 and a formal CISA advisory issued in early 2025.

Known victims517

Threat Level

CRITICAL

Tactics, Techniques & Procedures (TTPs)

CredentialTheft

  • Mimikatz

DefenseEvasion

  • EDRSandBlast
  • KillAV
  • ThrottleStop driver

DiscoveryEnum

  • Advanced IP Scanner
  • Navicat
  • PDQ Inventory
  • RoboCopy
  • SoftPerfect NetScan

Exfiltration

  • RClone

LOLBAS

  • BITSAdmin
  • Process Explorer
  • PsExec

Networking

  • Cloudflared
  • FRP
  • Ligolo
  • PuTTY
  • RevSocks

RMM-Tools

  • AnyDesk
  • Atera
  • HCL BigFix
  • N-Able
  • PDQ Deploy
  • +4 more
0

Check If You’re Affected

Search our database to see if your organization appears in medusa’s victim list.

Try it nowFree⌘K
Try

risk score · threat categories · sources · age · confidence — in one request

Other Active Ransomware Groups