Medusa (Windows)

First seen
2022-12-01 00:00:00
Malware type
ransomware
Family
Malware family
Profile updated
2026-07-07 13:17:09

Targeted industries: financial-services government-and-public-sector healthcare-and-pharmaceutical technology-and-telecommunications

Context

According to Unit 42, Medusa surfaced as a ransomware-as-a-service (RaaS) platform in late 2022 and gained notoriety in early 2023, primarily targeting Windows environments. Medusa should not be confused with a similarly named RaaS, MedusaLocker, which has been available since 2019.

Exploited vulnerabilities

  • CVE-2025-10035 (vulnerability)

Reports & references

  • Microsoft — Investigating Active Exploitation Of Cve 2025 10035 Goanywhere Managed File Transfer Vulnerability (report)
  • CISA — Aa25 071A (report)
  • bleepingcomputer.com — March 2023 Broke Ransomware Attack Records With 459 Incidents (report)
  • security.com — Lazarus Medusa Ransomware (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Medusa (report)
  • loginsoft.com — Medusa Ransomware Evolving Tactics In Modern Cyber Extortion (report)
  • Palo Alto Unit 42 — Medusa Ransomware Escalation New Leak Site (report)

External references