Medusa (Windows)
- First seen
- 2022-12-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Profile updated
- 2026-07-07 13:17:09
Targeted industries: financial-services government-and-public-sector healthcare-and-pharmaceutical technology-and-telecommunications
Context
According to Unit 42, Medusa surfaced as a ransomware-as-a-service (RaaS) platform in late 2022 and gained notoriety in early 2023, primarily targeting Windows environments. Medusa should not be confused with a similarly named RaaS, MedusaLocker, which has been available since 2019.
Exploited vulnerabilities
- CVE-2025-10035 (vulnerability)
Reports & references
- Microsoft — Investigating Active Exploitation Of Cve 2025 10035 Goanywhere Managed File Transfer Vulnerability (report)
- CISA — Aa25 071A (report)
- bleepingcomputer.com — March 2023 Broke Ransomware Attack Records With 459 Incidents (report)
- security.com — Lazarus Medusa Ransomware (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Medusa (report)
- loginsoft.com — Medusa Ransomware Evolving Tactics In Modern Cyber Extortion (report)
- Palo Alto Unit 42 — Medusa Ransomware Escalation New Leak Site (report)