Medusa Group
MITRE ATT&CK: G1051 View on attack.mitre.org
Aliases: Medusa Group
- First seen
- 2021-01-01 00:00:00
- Primary motivation
- financial-gain
- Sophistication
- advanced
- Resource level
- organization
- Actor type
- criminal
- Profile updated
- 2026-07-07 12:30:25
Targeted industries: financial-services government-and-public-sector healthcare-and-pharmaceutical manufacturing technology-and-telecommunications
Context
Medusa Group has been active since at least 2021 and was initially operated as a closed ransomware group before evolving into a Ransomware-as-a-Service (RaaS) operation. Some reporting indicates that certain attacks may still be conducted directly by the ransomware’s core developers. Public sources have also referred to the group as “Spearwing” or “Medusa Actors.” Medusa Group employs living-off-the-land techniques, frequently leveraging publicly available tools and common remote management software to conduct operations. The group engages in double extortion tactics, exfiltrating data prior to encryption and threatening to publish stolen information if ransom demands are not met. For initial access, Medusa Group has exploited publicly known vulnerabilities, conducted phishing campaigns, and used credentials or access purchased from Initial Access Brokers (IABs). The group is opportunistic and has targeted a wide range of sectors globally.
Detection coverage
- 9 YARA rules
- 991 Sigma rules
Malware & tools used
- Lateral Tool Transfer (attack-pattern)
- Windows Service (attack-pattern)
- Service Stop (attack-pattern)
- Native API (attack-pattern)
- Web Services (attack-pattern)
- Upload Tool (attack-pattern)
- Command Obfuscation (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Modify Registry (attack-pattern)
- Tool (attack-pattern)
- Local Account (attack-pattern)
- Social Media Accounts (attack-pattern)
- Exfiltration to Cloud Storage (attack-pattern)
- Clear Command History (attack-pattern)
- Acquire Access (attack-pattern)
- Web Protocols (attack-pattern)
- Disable or Modify System Firewall (attack-pattern)
- Hidden Window (attack-pattern)
- Network Share Discovery (attack-pattern)
- Multi-hop Proxy (attack-pattern)
- Exploit Public-Facing Application (attack-pattern)
- MMC (attack-pattern)
- Email Accounts (attack-pattern)
- Valid Accounts (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
Reports & references
- MITRE ATT&CK — G1051 (report)
- securityscorecard.com — Deep Dive Into Medusa Ransomware (report)
- CISA — Aa25 071A (report)
- intel471.com — Threat Hunting Case Study Medusa Ransomware (report)
- security.com — Medusa Ransomware Attacks (report)