Also known as: tracked as, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations, None publicly documented
Medusa Group originated around 2021 as a tightly controlled ransomware crew but has transitioned into a full‑blown Ransomware‑as‑a‑Service (RaaS) provider. Its attack toolkit blends ubiquitous Windows utilities—certutil, PowerShell, native command‑line tools—with bespoke payloads that include the Medusa engine and derivatives such as BlackByte. The operators augment their ransomware core with exfiltration modules like Rclone to ship stolen data directly to cloud storage providers before encryption, thereby enabling double‑extortion and increasing leverage over victims. Initial access is achieved through a spectrum of vectors: exploitation of CVEs in public software (e.g., ScreenConnect CVE‑2024‑1709 and Fortinet EMS CVE‑2023‑48788), spearphishing attachments, and purchased credentials from broker exchanges. Once inside they perform pervasive reconnaissance using built‑in Windows discovery commands (driverquery, net group) to locate security products, domain groups, and critical services. For persistence and lateral movement Medusa relies on native mechanisms such as Windows Management Instrumentation, scheduled tasks or container orchestration jobs, RMM tools like PDQ Deploy, and the exploitation of web shells in compromised Exchange servers. Their defense‑evasion arsenal includes driver hijacking (BYOVD) to disable security agents, hard‑coded blacklists that target anti‑malware binaries, firewall reconfiguration, and the use of masquerading techniques to obfuscate malicious processes. Finally, Medusa’s operational model is centered on a high‑volume, low‑cost subscription approach: delivering ransomware as a service while monetizing exfiltration support. This yields sustained revenue streams and broadens the group’s threat footprint across a diverse range of sectors worldwide.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Medusa Group has evolved from a closed ransomware clan into a sophisticated Ransomware‑as‑a‑Service operation that deploys double‑extortion tactics worldwide. It leverages public exploits, phishing, credential theft, and living‑off‑the‑land utilities—particularly driver hijacking and cloud‑based exfiltration via Rclone—to compromise large enterprises before encrypting data. The group’s broad industry targets span government, financial services, telecoms, defense, healthcare, energy, and many others across more than 30 countries, reflecting a financially driven motive rather than ideological or strategic targeting.
Goals & Targeting
The Medusa Group’s primary objective is monetary gain through ransom payment and data leaks. Their targeting strategy reflects pure profitability, reaching any institution that can afford to pay: government agencies, financial institutions, healthcare providers, telecom operators, energy utilities, defense contractors, and even educational and non‑profit entities. By exploiting widely deployed public software and using low‑cost credential theft or phishing operations, they lower entry barriers while maximizing potential payouts across multiple geographies.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Operationally, Medusa exhibits a high tempo of activity with rapid deployment across sectors and geographies. The group typically follows a pattern of initial compromise via public vulnerability or phishing, followed by an extensive assessment phase that seeks security software targets, domain groups, and network topology. Persistence is maintained through legitimate utilities and scheduled tasks while lateral movement leverages container orchestration jobs, WMI, RMM tools, and Exchange web shells. Their exfiltration strategy centers on cloud‑backed transfer (Rclone) that precedes the encryption step—a hallmark of double‑extortion campaigns. Past operations have included high‑profile attacks targeting large financial services firms, defense contractors, and healthcare providers across the United States, Europe, and Asia. The group's monetization model—charging subscription or one‑off contracts for ransomware delivery and providing “exfiltration support” in return—has resulted in a scalable threat landscape that can quickly evolve new variants or tactics to evade discovery.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The intelligence demonstrates moderate confidence in the Medusa Group’s core capabilities, tactics, and motivations based on corroborated indicators such as documented CVE exploitation and double‑extortion patterns. However, gaps remain regarding exact attribution timelines, full scope of tool usage, and specific campaign IDs. Ongoing validation through threat hunting, reverse engineering, and correlation with observed incidents is recommended to refine the threat profile further.
No campaigns linked yet.
No observed data linked yet.
96
Techniques
55
Tools
0
Campaigns
36
IOCs
0
Observed Data
14
Tactics