Medusa is a ransomware-as-a-service operation active since June 2021 that has targeted over 300 victims across critical infrastructure sectors including healthcare, education, legal, and manufacturing using double-extortion, with attacks surging 42% between 2023 and 2024 and a formal CISA advisory issued in early 2025. Known victims: 517 2 ransom note(s) on file
Objectives
Executive Summary
Medusa is a ransomware-as-a-service (RaaS) operation targeting critical infrastructure sectors with double extortion tactics, having impacted over 500 victims since its inception in 2021. The group's activities have surged by 42% between 2023 and 2024, prompting a formal CISA advisory in early 2025.
Goals & Targeting
Medusa's primary motivation is financial gain, achieved through ransomware attacks on organizations with high susceptibility to such threats. The group specifically targets sectors where ransoms are more likely to be paid, such as healthcare and education, due to potential disruptions in essential services. Medusa’s victims are often selected based on factors like slow backup recovery times or international operations that may complicate law enforcement responses.
Enhanced Description
Medusa is a sophisticated ransomware operation that emerged in June 2021 as a Ransomware-as-a-Service (RaaS) model. The group has targeted over 500 victims across critical infrastructure sectors, including healthcare, education, legal, and manufacturing. Medusa's operations are characterized by double extortion schemes, where victims are threatened with both data encryption and the release of stolen information unless a ransom is paid. This approach has made Medusa one of the most impactful ransomware groups in recent years. The group’s attacks have surged significantly since 2023, with activity increasing by 42% compared to the previous year. A formal advisory from the Cybersecurity and Infrastructure Security Agency (CISA) was issued in early 2025, recognizing Medusa as a critical threat to U.S. critical infrastructure.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Medusa's campaigns are highly targeted and efficient, often leveraging phishing emails with malicious attachments or links to gain initial access. The group’s operational tempo has increased significantly since 2023, with a noted focus on sectors that offer higher financial incentives for successful attacks. Notable past operations include the targeting of healthcare providers in late 2024, where Medusa exploited unpatched vulnerabilities to deploy its ransomware. Campaigns are often characterized by their speed and precision, with Medusa operators typically seeking to encrypt data quickly before defenders can respond.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in Medusa's operational details due to the availability of multiple ransom notes and IOCs. However, limited visibility into their internal structures and specific toolsets leaves some gaps in understanding their full capabilities.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
44
IOCs
0
Observed Data
0
Tactics