Medusa Ransomware
MITRE ATT&CK: S1244 View on attack.mitre.org
Aliases: Medusa Ransomware
- First seen
- 2021-01-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Related IoCs
- 4 (4 malicious)
- Last IoC activity
- 2026-08-12 14:22:58
- Profile updated
- 2026-07-07 13:19:04
Targeted industries: education-and-nonprofits financial-services healthcare-and-pharmaceutical manufacturing professional-services retail-and-hospitality technology-and-telecommunications
Context
Medusa Ransomware has been utilized in attacks since at least 2021. Medusa Ransomware has been known to be utilized in conjunction with living off the land techniques and remote management software. Medusa Ransomware has been used in campaigns associated with “double extortion” ransomware activity, where data is exfiltrated from victim environments prior to encryption, with threats to publish files if a ransom is not paid. Medusa Ransomware software was initially a closed ransomware variant which later evolved to a Ransomware as a Service (RaaS). Medusa Ransomware has impacted victims from a diverse range of sectors within a multitude of countries, and it is assessed Medusa Ransomware is used in an opportunistic manner.
Recent IoC activity
4 malicious indicators in Maltiverse are attributed to Medusa Ransomware (S1244). The 4 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | 9d3a0b086635005728f24d68cd62424aca74b8c033c0d55128aaf64c9eb7eaae | 2026-08-12 | 1 |
| file sample | 190ac2738235f43bf54eab629461e4ed0e3aa3afb92e9ef8a3406d1cb8cd5d44 | 2026-08-12 | 1 |
| file sample | b834a28d8f774f27d3202d4382b9aa1a6ba4ee43d3d3765938eab0352eefbbde | 2026-08-12 | 1 |
| file sample | RAN_Medusa_20260411.exe | 2026-08-07 | 4 |
Detection coverage
- 578 Sigma rules
Malware & tools used
- Network Share Discovery (attack-pattern)
- Security Software Discovery (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Selective Exclusion (attack-pattern)
- System Service Discovery (attack-pattern)
- Inhibit System Recovery (attack-pattern)
- Windows Service (attack-pattern)
- Process Discovery (attack-pattern)
- File Deletion (attack-pattern)
- Local Storage Discovery (attack-pattern)
- Service Stop (attack-pattern)
- Native API (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Hidden Window (attack-pattern)
- Inter-Process Communication (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Windows Command Shell (attack-pattern)
- System Information Discovery (attack-pattern)
- PowerShell (attack-pattern)
- System Time Discovery (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- Data Encrypted for Impact (attack-pattern)
Used by threat actors
- Medusa Group (threat-actor)
Reports & references
- securityscorecard.com — Deep Dive Into Medusa Ransomware (report)
- CISA — Aa25 071A (report)
- security.com — Medusa Ransomware Attacks (report)
- Palo Alto Unit 42 — Medusa Ransomware Escalation New Leak Site (report)
- MITRE ATT&CK — S1244 (report)