Vlad Pasca. (2024, January 1). A Deep Dive into Medusa Ransomware. Retrieved October 15, 2025.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1007 System Service Discovery |
MalwareMedusa Ransomware | Medusa Ransomware has leveraged an encoded list of services that it designates for termination. |
| T1027.013 Encrypted/Encoded File |
MalwareMedusa Ransomware | Medusa Ransomware has utilized XOR encrypted strings. |
| T1057 Process Discovery |
MalwareMedusa Ransomware | Medusa Ransomware has utilized an encoded list of the processes that it detects and terminates. |
| T1059.001 PowerShell |
MalwareMedusa Ransomware | Medusa Ransomware has launched PowerShell scripts for execution and defense evasion. |
| T1059.003 Windows Command Shell |
MalwareMedusa Ransomware | Medusa Ransomware has used `cmd.exe` to execute command on an infected host. |
| T1070.004 File Deletion |
MalwareMedusa Ransomware | Medusa Ransomware has the ability to delete itself after execution. Medusa Ransomware also has the ability to delete itself after execution through the command `cmd /c ping localhost -n 3 > nul & del`. |
| T1082 System Information Discovery |
MalwareMedusa Ransomware | Medusa Ransomware has collected data from the SMBIOS firmware table using `GetSystemFirmwareTable`. |
| T1083 File and Directory Discovery |
GroupMedusa Group | Medusa Group has searched for files within the victim environment for encryption and exfiltration. Medusa Group has also identified files associated with remote management services. |
| T1083 File and Directory Discovery |
MalwareMedusa Ransomware | Medusa Ransomware has searched for files within the victim environment for encryption and exfiltration. Medusa Ransomware has also identified files associated with remote management services. |
| T1106 Native API |
MalwareMedusa Ransomware | Medusa Ransomware has leveraged Windows Native API functions to execute payloads. |
| T1106 Native API |
GroupMedusa Group | Medusa Group has leveraged Windows Native API functions to execute payloads. |
| T1124 System Time Discovery |
MalwareMedusa Ransomware | Medusa Ransomware has discovered device uptime through `GetTickCount()`. |
| T1135 Network Share Discovery |
MalwareMedusa Ransomware | Medusa Ransomware has identified networked drives. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareMedusa Ransomware | Medusa Ransomware has decoded XOR encrypted strings prior to execution in memory. |
| T1219 Remote Access Tools |
GroupMedusa Group | Medusa Group has leveraged Remote Access Software for lateral movement and data exfiltration. Medusa Group has also been known to utilize Remote Access Software such as AnyDesk, Atera, ConnectWise, eHorus, N-Able, PDQ Deploy, PDQ Inventory, SimpleHelp and Splashtop. |
| T1486 Data Encrypted for Impact |
MalwareMedusa Ransomware | Medusa Ransomware has encrypted files using AES-256 encryption, which then appends the file extension “.medusa” to encrypted files and leaves a ransomware note named “!READ_ME_MEDUSA!!!.txt.” |
| T1486 Data Encrypted for Impact |
GroupMedusa Group | Medusa Group has encrypted files using AES-256 encryption which then appends the file extension “.medusa” to encrypted files and leaves a ransomware note named “!READ_ME_MEDUSA!!!.txt.” |
| T1489 Service Stop |
MalwareMedusa Ransomware | Medusa Ransomware has the capability to terminate services related to backups, security, databases, communication, filesharing and websites. Medusa Ransomware has also utilized the `taskkill /F /IM <process> /T` command to stop targeted processes and `net stop <process>` command to stop designated services. |
| T1489 Service Stop |
GroupMedusa Group | Medusa Group has terminated services related to backups, security, databases, communication, filesharing and websites. |
| T1490 Inhibit System Recovery |
MalwareMedusa Ransomware | Medusa Ransomware has deleted recovery files such as shadow copies using `vssadmin.exe`. |
| T1490 Inhibit System Recovery |
GroupMedusa Group | Medusa Group has deleted recovery files such as shadow copies using `vssadmin.exe`. |
| T1543.003 Windows Service |
MalwareMedusa Ransomware | Medusa Ransomware has created a new PowerShell process using the `CreateProcessA` API. |
| T1559 Inter-Process Communication |
MalwareMedusa Ransomware | Medusa Ransomware has leveraged the `CreatePipe` API to enable inter-process communication. |
| T1564.003 Hidden Window |
MalwareMedusa Ransomware | Medusa Ransomware has utilized the `ShowWindow` function to hide current window. |
| T1564.003 Hidden Window |
GroupMedusa Group | Medusa Group has utilized the `ShowWindow` API function to hide the current window. |
| T1657 Financial Theft |
GroupMedusa Group | Medusa Group has stolen and encrypted victims' data in order to extort victims into paying a ransom. |
| T1679 Selective Exclusion |
MalwareMedusa Ransomware | Medusa Ransomware has avoided specified files, file extensions and folders to ensure successful execution of the payload and continued operations of the impacted device. |
| T1680 Local Storage Discovery |
MalwareMedusa Ransomware | Medusa Ransomware has enumerated logical drives on infected hosts. |
| T1685 Disable or Modify Tools |
MalwareMedusa Ransomware | Medusa Ransomware has terminated antivirus services utilizing the gaze.exe executable. Medusa Ransomware has also terminated antivirus services utilizing PowerShell scripts. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.