MEDUSA

MITRE ATT&CK: S1220 View on attack.mitre.org

Aliases: MEDUSA

Malware type
rootkit
Family
Malware family
Operating systems
linux
Related IoCs
12 (4 malicious)
Last IoC activity
2026-09-02 02:37:28
Profile updated
2026-07-07 13:51:59

Context

MEDUSA is an open-source rootkit that is capable of dynamic linker hijacking, command execution, and logging credentials.

Recent IoC activity

4 malicious indicators in Maltiverse are attributed to MEDUSA (S1220). The 4 most recently updated:

TypeIndicatorUpdatedSources
URL https://t.me/anbshbb 2026-09-02 1
URL https://t.me/xpembeppep2p2 2026-09-01 1
file sample RAN_Medusa_20260411.exe 2026-08-07 4
file sample ad97778e3b922b7766712be17d309974fa92dd9dacf088ecd06b1d3cda049a64 2026-07-18 1

Detection coverage

  • 3 YARA rules
  • 3 Sigma rules

Malware & tools used

  • SSH Hijacking (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Rootkit (attack-pattern)
  • Dynamic Linker Hijacking (attack-pattern)

Used by threat actors

  • RedPenguin (campaign)
  • UNC3886 (threat-actor)
  • LockBit Affiliate Citrix Bleed Exploits (campaign)

Detection rules

  • MALPEDIA_Win_Medusa_Auto (yara-rule)
  • EMBEERESEARCH_Win_Medusa_Bytecodes (yara-rule)
  • MALPEDIA_Win_Medusa_Http_Auto (yara-rule)

Reports & references

  • ransomlook.io — Medusa (report)
  • twitter.com — 1285144962695340032 (report)
  • threatfabric.com — Partners In Crime Medusa Cabassous (report)
  • threatfabric.com — The Rage Of Android Banking Trojans (report)
  • news.drweb.com — Show (report)
  • web.archive.org — Globalthreatintelreport (report)
  • arbornetworks.com — Medusahttp Ddos Slithers Back Spotlight (report)
  • zerophagemalware.com — Rig Ek Via Malvertising Drops A Miner (report)
  • MITRE ATT&CK — S1220 (report)
  • cloud.google.com — Uncovering Unc3886 Espionage Operations (report)

External references