Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Medusa Group

Also known as: tracked as, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations, None publicly documented

Description

Medusa Group originated around 2021 as a tightly controlled ransomware crew but has transitioned into a full‑blown Ransomware‑as‑a‑Service (RaaS) provider. Its attack toolkit blends ubiquitous Windows utilities—certutil, PowerShell, native command‑line tools—with bespoke payloads that include the Medusa engine and derivatives such as BlackByte. The operators augment their ransomware core with exfiltration modules like Rclone to ship stolen data directly to cloud storage providers before encryption, thereby enabling double‑extortion and increasing leverage over victims. Initial access is achieved through a spectrum of vectors: exploitation of CVEs in public software (e.g., ScreenConnect CVE‑2024‑1709 and Fortinet EMS CVE‑2023‑48788), spearphishing attachments, and purchased credentials from broker exchanges. Once inside they perform pervasive reconnaissance using built‑in Windows discovery commands (driverquery, net group) to locate security products, domain groups, and critical services. For persistence and lateral movement Medusa relies on native mechanisms such as Windows Management Instrumentation, scheduled tasks or container orchestration jobs, RMM tools like PDQ Deploy, and the exploitation of web shells in compromised Exchange servers. Their defense‑evasion arsenal includes driver hijacking (BYOVD) to disable security agents, hard‑coded blacklists that target anti‑malware binaries, firewall reconfiguration, and the use of masquerading techniques to obfuscate malicious processes. Finally, Medusa’s operational model is centered on a high‑volume, low‑cost subscription approach: delivering ransomware as a service while monetizing exfiltration support. This yields sustained revenue streams and broadens the group’s threat footprint across a diverse range of sectors worldwide.

Goals & Targeting

Targeted Sectors

Government
Financial services
Telecommunications
Defense
Healthcare
Education
Manufacturing
Critical infrastructure
Non profit
Media
Energy
Pharmaceutical
Aviation
Hospitality
Aerospace
Retail
Information technology
Think tank
Transportation
Mining
Chemical
Gaming
Legal services
Nuclear
Entertainment
Oil gas
Maritime
Construction
Utilities

Targeted Countries / Regions

US
CN
RU
GB
IR
VN
AU
JP
IL
SA
PK
TW
AE
UA
DE
SG
KR
IN
CA
BY
TR
MX
ES
PL
IT
RO
FR
NG
KP
LB
AZ
KZ

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 5 hours ago

Executive Summary

Medusa Group has evolved from a closed ransomware clan into a sophisticated Ransomware‑as‑a‑Service operation that deploys double‑extortion tactics worldwide. It leverages public exploits, phishing, credential theft, and living‑off‑the‑land utilities—particularly driver hijacking and cloud‑based exfiltration via Rclone—to compromise large enterprises before encrypting data. The group’s broad industry targets span government, financial services, telecoms, defense, healthcare, energy, and many others across more than 30 countries, reflecting a financially driven motive rather than ideological or strategic targeting.

Goals & Targeting

The Medusa Group’s primary objective is monetary gain through ransom payment and data leaks. Their targeting strategy reflects pure profitability, reaching any institution that can afford to pay: government agencies, financial institutions, healthcare providers, telecom operators, energy utilities, defense contractors, and even educational and non‑profit entities. By exploiting widely deployed public software and using low‑cost credential theft or phishing operations, they lower entry barriers while maximizing potential payouts across multiple geographies.

Enhanced Description

Key Capabilities

  • Living‑off‑the‑land tactics
  • Reusing publicly available utilities (certutil, PowerShell, Rclone)
  • Double extortion: exfiltration before encryption
  • Exploiting public vulnerabilities (e.g., ScreenConnect CVE‑2024‑1709, Fortinet EMS CVE‑2023‑48788)
  • Phishing and spearphishing attachments
  • Credential theft via purchased credentials or broker exchanges
  • Driver hijacking / BYOVD to disable security software
  • Legitimate remote management/deployment tools for lateral movement (PDQ Deploy, RMM)
  • Webshell deployment on Microsoft Exchange servers for persistence and pivoting
  • Native Windows discovery techniques (net group, driverquery)
  • Cloud‑based exfiltration via Rclone

MITRE ATT&CK Tactics

Initial Access
Discovery
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Acquisition
Collection
Lateral Movement
Exfiltration
Impact

ATT&CK Techniques

T1190
T1078
T1566.001
T1041
T1025
T1105
T1059
T1059.003
T1059.001
T1069.002
T1074
T1053.005
T1047
T1037
T1033
T1583
T1003
T1543
T1053.007
T1548.002
T1114
T1489
T1652
T1087.001
T1543.003
T1053.003
T1069.002
T1559.001
T1553.002
T1135
T1082
T1071
T1106
T1070.003
T1219
T1036
T1055
T1608.002
T1021
T1112
T1505.003
T1078.001
T1585.002
T1003.001
T1548
T1016
T1087
T1090
T1136.002
T1070
T1083
T1102
T1657
T1583.006
T1057
T1072
T1546.001
T1069.001
T1098
T1048
T1027
T1486
T1690
T1556.002
T1573.002
T1567.002
T1570
T1518.001
T1564.003
T1053.002
T1529
T1127
T1218.014

Software / Tooling

Medusa Ransomware Engine
BlackByte
Rclone
certutil
PowerShell
PsExec
PDQ Deploy
Remote Management Tools (RMM)
ScreenConnect
Fortinet EMS Exploit
Exchange Webshells
Web Shell
Credential Dumping Utilities
Exfiltration Scripts

Campaigns & Victims

Operationally, Medusa exhibits a high tempo of activity with rapid deployment across sectors and geographies. The group typically follows a pattern of initial compromise via public vulnerability or phishing, followed by an extensive assessment phase that seeks security software targets, domain groups, and network topology. Persistence is maintained through legitimate utilities and scheduled tasks while lateral movement leverages container orchestration jobs, WMI, RMM tools, and Exchange web shells. Their exfiltration strategy centers on cloud‑backed transfer (Rclone) that precedes the encryption step—a hallmark of double‑extortion campaigns. Past operations have included high‑profile attacks targeting large financial services firms, defense contractors, and healthcare providers across the United States, Europe, and Asia. The group's monetization model—charging subscription or one‑off contracts for ransomware delivery and providing “exfiltration support” in return—has resulted in a scalable threat landscape that can quickly evolve new variants or tactics to evade discovery.

IOC Patterns

  • CVE exploitation (ScreenConnect CVE-2024-1709, Fortinet EMS CVE-2023-48788)
  • Driver hijacking / BYOVD against security software
  • Domain group enumeration using net group
  • Cloud storage exfiltration via Rclone or similar tools
  • Webshell deployment on Microsoft Exchange servers

Recommended Actions

  • Patch all public‑facing applications and services immediately, especially those with known CVEs; establish a dedicated vulnerability management process. Monitor for unauthorized driver installations and signature changes—implement driver signing enforcement and audit mechanisms to detect BYOVD techniques. Block or alert on outbound traffic to commercial cloud storage providers (e.g., S3) that are not part of approved workflows; monitor Rclone usage via endpoint detection. Enforce MFA and stringent credential‑management policies, including short‑lived credentials and monitoring of credential‑broker purchases. Implement network segmentation and micro‑segmentation to limit lateral movement and restrict remote management tool use across departmental boundaries. Deploy an EDR that can detect native Windows discovery commands (driverquery, net group), scheduled tasks, WMI activity, and container orchestration job creation. Secure Microsoft Exchange servers by disabling web shell capabilities, monitoring PowerShell scripts, and enforcing Application Control rules. Maintain a list of known security‑product binaries and block attempts to manipulate them via hard‑coded blacklists or runtime integrity checks. Continuously update threat intelligence feeds on emerging malware families (Medusa, BlackByte) and CVEs to refine detection rules.

Suggested Tags

ransomware
RaaS
double-extortion
living-off-the-land
phishing
credential-steal
driver-hijacking
cloud-exfiltration
CVE-exploitation
Windows
certutil
PowerShell
PDQ Deploy
BYOVD
webshell
Exchange
Rclone

Confidence Assessment

The intelligence demonstrates moderate confidence in the Medusa Group’s core capabilities, tactics, and motivations based on corroborated indicators such as documented CVE exploitation and double‑extortion patterns. However, gaps remain regarding exact attribution timelines, full scope of tool usage, and specific campaign IDs. Ongoing validation through threat hunting, reverse engineering, and correlation with observed incidents is recommended to refine the threat profile further.

ATT&CK Techniques

Command & Control
9 techniques
Defense impairment
6 techniques
Discovery
14 techniques
Execution
14 techniques
Impact
5 techniques
Resource Development
7 techniques
Stealth
16 techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. CISA Medusa Group Medusa Ransomware March 2025 — Cybersecurity and Infrastructure Security Agency. (2025, March 12). AA25-071A #StopRansomware: Medusa Ransomware. Retrieved October 15, 2025.
  2. Intel471 Medusa Ransomware May 2025 — Intel471. (2025, May 14). Threat hunting case study: Medusa ransomware. Retrieved October 15, 2025.
  3. Broadcom Medusa Ransomware Medusa Group March 2025 — Threat Hunter Team Symantec and Carbon Black. (2025, March 6). Medusa Ransomware Activity Continues to Increase. Retrieved October 15, 2025.
  4. Security Scorecard Medusa Ransomware January 2024 — Vlad Pasca. (2024, January 1). A Deep Dive into Medusa Ransomware. Retrieved October 15, 2025.
  5. attack.mitre.org — Cited by web research for: Sandworm Team
  6. opensecurityarchitecture.org — Cited by web research for: T1055
  7. attack.mitre.org — Cited by web research for: T1059
  8. https://mallory.ai/actors/019ab9bd-c69d-79aa-8646-dc98da84d98e — Cited by AI analysis.

Intel Summary

96

Techniques

55

Tools

0

Campaigns

36

IOCs

0

Observed Data

14

Tactics

Tags

Ransomware
Critical Infrastructure
Phishing
Double extortion
Living-off-the-land
Financial theft
Medusa Group
Ransomware-as-a-Service
Double Extortion
Living-off-the-Land
Public‑Facing Vulnerability Exploitation
Credential Compromise
Cloud Exfiltration
Driver-Based Defense Evasion
Rclone
PDQ Deploy
Webshell
Exchange Server
PowerShell
Certutil
ransomware
RaaS
double-extortion
living-off-the-land
phishing
credential-steal
driver-hijacking
cloud-exfiltration
CVE-exploitation
Windows
certutil
BYOVD
webshell
Exchange

Details

MITRE ID
G1051
Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--918da025-04bd-48af-b6c4-f3e4d1b915eb
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.