Threat Hunter Team Symantec and Carbon Black. (2025, March 6). Medusa Ransomware Activity Continues to Increase. Retrieved October 15, 2025.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.003 NTDS |
GroupMedusa Group | Medusa Group has accessed the ntds.dit file to engage in credential dumping. |
| T1007 System Service Discovery |
MalwareMedusa Ransomware | Medusa Ransomware has leveraged an encoded list of services that it designates for termination. |
| T1018 Remote System Discovery |
GroupMedusa Group | Medusa Group has used PDQ Inventory to get an inventory of the endpoints on the network. |
| T1033 System Owner/User Discovery |
GroupMedusa Group | Medusa Group has utilized PsExec to execute `quser` to discover the user session information. |
| T1046 Network Service Discovery |
GroupMedusa Group | Medusa Group has the capability to use living off the land (LOTL) binaries to perform network enumeration. Medusa Group has also utilized the publicly available scanning tool SoftPerfect Network Scanner (`netscan.exe`) to discover device hostnames and network services. |
| T1057 Process Discovery |
MalwareMedusa Ransomware | Medusa Ransomware has utilized an encoded list of the processes that it detects and terminates. |
| T1070.004 File Deletion |
MalwareMedusa Ransomware | Medusa Ransomware has the ability to delete itself after execution. Medusa Ransomware also has the ability to delete itself after execution through the command `cmd /c ping localhost -n 3 > nul & del`. |
| T1087.001 Local Account |
GroupMedusa Group | Medusa Group has leveraged `net user` for account discovery. |
| T1090.003 Multi-hop Proxy |
GroupMedusa Group | Medusa Group has used TOR nodes for communications. |
| T1105 Ingress Tool Transfer |
GroupMedusa Group | Medusa Group has leveraged certutil, PowerShell, and Windows Command to download additional tools to include RMM services. Medusa Group has also engaged in “Bring Your Own Vulnerable Driver” (BYOVD) and downloaded vulnerable or signed drivers to the victim environment to disable security tools. |
| T1135 Network Share Discovery |
MalwareMedusa Ransomware | Medusa Ransomware has identified networked drives. |
| T1190 Exploit Public-Facing Application |
GroupMedusa Group | Medusa Group has leveraged public facing vulnerabilities in their campaigns against victim organizations to gain initial access. Medusa Group has also utilized CVE-2024-1709 in ScreenConnect, and CVE-2023-48788 in Fortinet EMS for initial access to victim environments. |
| T1219 Remote Access Tools |
GroupMedusa Group | Medusa Group has leveraged Remote Access Software for lateral movement and data exfiltration. Medusa Group has also been known to utilize Remote Access Software such as AnyDesk, Atera, ConnectWise, eHorus, N-Able, PDQ Deploy, PDQ Inventory, SimpleHelp and Splashtop. |
| T1486 Data Encrypted for Impact |
MalwareMedusa Ransomware | Medusa Ransomware has encrypted files using AES-256 encryption, which then appends the file extension “.medusa” to encrypted files and leaves a ransomware note named “!READ_ME_MEDUSA!!!.txt.” |
| T1486 Data Encrypted for Impact |
GroupMedusa Group | Medusa Group has encrypted files using AES-256 encryption which then appends the file extension “.medusa” to encrypted files and leaves a ransomware note named “!READ_ME_MEDUSA!!!.txt.” |
| T1489 Service Stop |
MalwareMedusa Ransomware | Medusa Ransomware has the capability to terminate services related to backups, security, databases, communication, filesharing and websites. Medusa Ransomware has also utilized the `taskkill /F /IM <process> /T` command to stop targeted processes and `net stop <process>` command to stop designated services. |
| T1489 Service Stop |
GroupMedusa Group | Medusa Group has terminated services related to backups, security, databases, communication, filesharing and websites. |
| T1490 Inhibit System Recovery |
GroupMedusa Group | Medusa Group has deleted recovery files such as shadow copies using `vssadmin.exe`. |
| T1490 Inhibit System Recovery |
MalwareMedusa Ransomware | Medusa Ransomware has deleted recovery files such as shadow copies using `vssadmin.exe`. |
| T1567.002 Exfiltration to Cloud Storage |
GroupMedusa Group | Medusa Group has utilized Rclone to exfiltrate data from victim environments to cloud storage. |
| T1569.002 Service Execution |
GroupMedusa Group | Medusa Group has utilized PsExec to execute scripts and commands within victim environments. Medusa Group has also used the Windows service RoboCopy to search and copy data for exfiltration. |
| T1570 Lateral Tool Transfer |
GroupMedusa Group | Medusa Group has utilized legitimate software services such as PDQ Deploy to transfer malicious binaries and tools to other victimized hosts within the target environment. |
| T1588.002 Tool |
GroupMedusa Group | Medusa Group has obtained and leveraged numerous RMM services, along with publicly available tools used for scanning. Medusa Group has utilized tools such as Advanced IP Scanner and SoftPerfect Network scanner for user, system and network discovery. Medusa Group has also acquired tools for command and control and defense evasion which include tunneling tools Ligolo and Cloudflared. |
| T1657 Financial Theft |
GroupMedusa Group | Medusa Group has stolen and encrypted victims' data in order to extort victims into paying a ransom. |
| T1679 Selective Exclusion |
MalwareMedusa Ransomware | Medusa Ransomware has avoided specified files, file extensions and folders to ensure successful execution of the payload and continued operations of the impacted device. |
| T1685 Disable or Modify Tools |
GroupMedusa Group | Medusa Group has terminated antivirus services utilizing the gaze.exe executable and utilizing `psexec.exe`. Medusa Group has also leveraged I/O control codes (IOCTLs) for terminating and deleting processes of identified security tools. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.