Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors medusa

Description

Medusa is a ransomware-as-a-service operation active since June 2021 that has targeted over 300 victims across critical infrastructure sectors including healthcare, education, legal, and manufacturing using double-extortion, with attacks surging 42% between 2023 and 2024 and a formal CISA advisory issued in early 2025. Known victims: 517 2 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Medusa is a ransomware-as-a-service (RaaS) operation targeting critical infrastructure sectors with double extortion tactics, having impacted over 500 victims since its inception in 2021. The group's activities have surged by 42% between 2023 and 2024, prompting a formal CISA advisory in early 2025.

Goals & Targeting

Medusa's primary motivation is financial gain, achieved through ransomware attacks on organizations with high susceptibility to such threats. The group specifically targets sectors where ransoms are more likely to be paid, such as healthcare and education, due to potential disruptions in essential services. Medusa’s victims are often selected based on factors like slow backup recovery times or international operations that may complicate law enforcement responses.

Enhanced Description

Medusa is a sophisticated ransomware operation that emerged in June 2021 as a Ransomware-as-a-Service (RaaS) model. The group has targeted over 500 victims across critical infrastructure sectors, including healthcare, education, legal, and manufacturing. Medusa's operations are characterized by double extortion schemes, where victims are threatened with both data encryption and the release of stolen information unless a ransom is paid. This approach has made Medusa one of the most impactful ransomware groups in recent years. The group’s attacks have surged significantly since 2023, with activity increasing by 42% compared to the previous year. A formal advisory from the Cybersecurity and Infrastructure Security Agency (CISA) was issued in early 2025, recognizing Medusa as a critical threat to U.S. critical infrastructure.

Key Capabilities

  • Ransomware deployment with double extortion tactics
  • Sophisticated phishing campaigns using spear-phishing emails
  • Exploitation of unpatched vulnerabilities in target environments
  • Lateral movement within networks to maximize impact
  • Custom-built encryption tools for data exfiltration and ransom demands
  • Coordinated attacks on critical infrastructure sectors
  • Use of onion-based communication channels for C2 infrastructure

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Credential Access
Discovery
Lateral Movement

ATT&CK Techniques

T1566.001 - Double extortion/ransom in conjunction with file encryption (Data Exfiltration)
T1059.003 - Phishing via spear-phishing attachment
T1078.001 -Credential dumping via credential theft
T1233 - Discovery of domain information for external access
T1048 - Account Access Removal (e.g., removal of user accounts)
T1055 - Process Injection (e.g., injecting malicious code into legitimate processes)

Software / Tooling

Custom ransomware
Double extortion tools
Phishing toolkit (spear-phishing campaigns)
C2 communication channels (e.g., Tor, onion services)
Exploitation frameworks (vulnerability targeting)

Campaigns & Victims

Medusa's campaigns are highly targeted and efficient, often leveraging phishing emails with malicious attachments or links to gain initial access. The group’s operational tempo has increased significantly since 2023, with a noted focus on sectors that offer higher financial incentives for successful attacks. Notable past operations include the targeting of healthcare providers in late 2024, where Medusa exploited unpatched vulnerabilities to deploy its ransomware. Campaigns are often characterized by their speed and precision, with Medusa operators typically seeking to encrypt data quickly before defenders can respond.

IOC Patterns

  • Spear-phishing emails targeting critical infrastructure sectors
  • Landed documents containing malicious scripts (e.g., Excel macros)
  • C2 communication via Tor or dark web channels
  • Presence of encryption binaries within victim networks
  • Ransom notes with specific payment instructions and deadlines
  • Exfiltration attempts targeting sensitive data repositories

Recommended Actions

  • Implement multi-layered email filtering to detect phishing emails
  • Monitor for suspicious activity in network shares and backups
  • Conduct regular vulnerability scanning and patch management
  • Enforce strict access controls and least privilege policies
  • Train employees to recognize spear-phishing attempts
  • Deploy endpoint detection and response (EDR) solutions
  • Maintain offline backups of critical systems and regularly test restoration

Suggested Tags

ransomware
double extortion
critical infrastructure
financial-gain
cybercrime
healthcare-targeting
education-sector
manufacturing-sector

Confidence Assessment

High confidence in Medusa's operational details due to the availability of multiple ransom notes and IOCs. However, limited visibility into their internal structures and specific toolsets leaves some gaps in understanding their full capabilities.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

44

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Healthcare Targeting
Critical Infrastructure
ransomware
double extortion
critical infrastructure
financial-gain
cybercrime
healthcare-targeting
education-sector
manufacturing-sector

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Jan 11, 2023
Last Seen
Feb 13, 2026
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.