ATT&CKReferencesSecurity Scorecard Medusa Ransomware January 2024

Security Scorecard Medusa Ransomware January 2024

Vlad Pasca. (2024, January 1). A Deep Dive into Medusa Ransomware. Retrieved October 15, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples29

TechniqueUsed byProcedure example
T1007
System Service Discovery
MalwareMedusa Ransomware

Medusa Ransomware has leveraged an encoded list of services that it designates for termination.

T1027.013
Encrypted/Encoded File
MalwareMedusa Ransomware

Medusa Ransomware has utilized XOR encrypted strings.

T1057
Process Discovery
MalwareMedusa Ransomware

Medusa Ransomware has utilized an encoded list of the processes that it detects and terminates.

T1059.001
PowerShell
MalwareMedusa Ransomware

Medusa Ransomware has launched PowerShell scripts for execution and defense evasion.

T1059.003
Windows Command Shell
MalwareMedusa Ransomware

Medusa Ransomware has used `cmd.exe` to execute command on an infected host.

T1070.004
File Deletion
MalwareMedusa Ransomware

Medusa Ransomware has the ability to delete itself after execution. Medusa Ransomware also has the ability to delete itself after execution through the command `cmd /c ping localhost -n 3 > nul & del`.

T1082
System Information Discovery
MalwareMedusa Ransomware

Medusa Ransomware has collected data from the SMBIOS firmware table using `GetSystemFirmwareTable`.

T1083
File and Directory Discovery
GroupMedusa Group

Medusa Group has searched for files within the victim environment for encryption and exfiltration. Medusa Group has also identified files associated with remote management services.

T1083
File and Directory Discovery
MalwareMedusa Ransomware

Medusa Ransomware has searched for files within the victim environment for encryption and exfiltration. Medusa Ransomware has also identified files associated with remote management services.

T1106
Native API
MalwareMedusa Ransomware

Medusa Ransomware has leveraged Windows Native API functions to execute payloads.

T1106
Native API
GroupMedusa Group

Medusa Group has leveraged Windows Native API functions to execute payloads.

T1124
System Time Discovery
MalwareMedusa Ransomware

Medusa Ransomware has discovered device uptime through `GetTickCount()`.

T1135
Network Share Discovery
MalwareMedusa Ransomware

Medusa Ransomware has identified networked drives.

T1140
Deobfuscate/Decode Files or Information
MalwareMedusa Ransomware

Medusa Ransomware has decoded XOR encrypted strings prior to execution in memory.

T1219
Remote Access Tools
GroupMedusa Group

Medusa Group has leveraged Remote Access Software for lateral movement and data exfiltration. Medusa Group has also been known to utilize Remote Access Software such as AnyDesk, Atera, ConnectWise, eHorus, N-Able, PDQ Deploy, PDQ Inventory, SimpleHelp and Splashtop.

T1486
Data Encrypted for Impact
MalwareMedusa Ransomware

Medusa Ransomware has encrypted files using AES-256 encryption, which then appends the file extension “.medusa” to encrypted files and leaves a ransomware note named “!READ_ME_MEDUSA!!!.txt.”

T1486
Data Encrypted for Impact
GroupMedusa Group

Medusa Group has encrypted files using AES-256 encryption which then appends the file extension “.medusa” to encrypted files and leaves a ransomware note named “!READ_ME_MEDUSA!!!.txt.”

T1489
Service Stop
MalwareMedusa Ransomware

Medusa Ransomware has the capability to terminate services related to backups, security, databases, communication, filesharing and websites. Medusa Ransomware has also utilized the `taskkill /F /IM <process> /T` command to stop targeted processes and `net stop <process>` command to stop designated services.

T1489
Service Stop
GroupMedusa Group

Medusa Group has terminated services related to backups, security, databases, communication, filesharing and websites.

T1490
Inhibit System Recovery
MalwareMedusa Ransomware

Medusa Ransomware has deleted recovery files such as shadow copies using `vssadmin.exe`.

T1490
Inhibit System Recovery
GroupMedusa Group

Medusa Group has deleted recovery files such as shadow copies using `vssadmin.exe`.

T1543.003
Windows Service
MalwareMedusa Ransomware

Medusa Ransomware has created a new PowerShell process using the `CreateProcessA` API.

T1559
Inter-Process Communication
MalwareMedusa Ransomware

Medusa Ransomware has leveraged the `CreatePipe` API to enable inter-process communication.

T1564.003
Hidden Window
MalwareMedusa Ransomware

Medusa Ransomware has utilized the `ShowWindow` function to hide current window.

T1564.003
Hidden Window
GroupMedusa Group

Medusa Group has utilized the `ShowWindow` API function to hide the current window.

T1657
Financial Theft
GroupMedusa Group

Medusa Group has stolen and encrypted victims' data in order to extort victims into paying a ransom.

T1679
Selective Exclusion
MalwareMedusa Ransomware

Medusa Ransomware has avoided specified files, file extensions and folders to ensure successful execution of the payload and continued operations of the impacted device.

T1680
Local Storage Discovery
MalwareMedusa Ransomware

Medusa Ransomware has enumerated logical drives on infected hosts.

T1685
Disable or Modify Tools
MalwareMedusa Ransomware

Medusa Ransomware has terminated antivirus services utilizing the gaze.exe executable. Medusa Ransomware has also terminated antivirus services utilizing PowerShell scripts.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.