MEDUSA
MITRE ATT&CK: S1220 View on attack.mitre.org
Aliases: MEDUSA
- Malware type
- rootkit
- Family
- Malware family
- Operating systems
- linux
- Related IoCs
- 12 (4 malicious)
- Last IoC activity
- 2026-09-02 02:37:28
- Profile updated
- 2026-07-07 13:51:59
Context
MEDUSA is an open-source rootkit that is capable of dynamic linker hijacking, command execution, and logging credentials.
Recent IoC activity
4 malicious indicators in Maltiverse are attributed to MEDUSA (S1220). The 4 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| URL | https://t.me/anbshbb | 2026-09-02 | 1 |
| URL | https://t.me/xpembeppep2p2 | 2026-09-01 | 1 |
| file sample | RAN_Medusa_20260411.exe | 2026-08-07 | 4 |
| file sample | ad97778e3b922b7766712be17d309974fa92dd9dacf088ecd06b1d3cda049a64 | 2026-07-18 | 1 |
Detection coverage
- 3 YARA rules
- 3 Sigma rules
Malware & tools used
- SSH Hijacking (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Rootkit (attack-pattern)
- Dynamic Linker Hijacking (attack-pattern)
Used by threat actors
- RedPenguin (campaign)
- UNC3886 (threat-actor)
- LockBit Affiliate Citrix Bleed Exploits (campaign)
Detection rules
- MALPEDIA_Win_Medusa_Auto (yara-rule)
- EMBEERESEARCH_Win_Medusa_Bytecodes (yara-rule)
- MALPEDIA_Win_Medusa_Http_Auto (yara-rule)
Reports & references
- ransomlook.io — Medusa (report)
- twitter.com — 1285144962695340032 (report)
- threatfabric.com — Partners In Crime Medusa Cabassous (report)
- threatfabric.com — The Rage Of Android Banking Trojans (report)
- news.drweb.com — Show (report)
- web.archive.org — Globalthreatintelreport (report)
- arbornetworks.com — Medusahttp Ddos Slithers Back Spotlight (report)
- zerophagemalware.com — Rig Ek Via Malvertising Drops A Miner (report)
- MITRE ATT&CK — S1220 (report)
- cloud.google.com — Uncovering Unc3886 Espionage Operations (report)