ATT&CKSoftwareMedusa Ransomware

Medusa Ransomware

S1244

Malware.View on attack.mitre.org

About this malware

Medusa Ransomware has been utilized in attacks since at least 2021. Medusa Ransomware has been known to be utilized in conjunction with living off the land techniques and remote management software. Medusa Ransomware has been used in campaigns associated with “double extortion” ransomware activity, where data is exfiltrated from victim environments prior to encryption, with threats to publish files if a ransom is not paid. Medusa Ransomware software was initially a closed ransomware variant which later evolved to a Ransomware as a Service (RaaS). Medusa Ransomware has impacted victims from a diverse range of sectors within a multitude of countries, and it is assessed Medusa Ransomware is used in an opportunistic manner.

Techniques used22

Procedure examples22

TechniqueProcedure example
T1007
System Service Discovery

Medusa Ransomware has leveraged an encoded list of services that it designates for termination.

T1027.013
Encrypted/Encoded File

Medusa Ransomware has utilized XOR encrypted strings.

T1057
Process Discovery

Medusa Ransomware has utilized an encoded list of the processes that it detects and terminates.

T1059.001
PowerShell

Medusa Ransomware has launched PowerShell scripts for execution and defense evasion.

T1059.003
Windows Command Shell

Medusa Ransomware has used `cmd.exe` to execute command on an infected host.

T1070.004
File Deletion

Medusa Ransomware has the ability to delete itself after execution. Medusa Ransomware also has the ability to delete itself after execution through the command `cmd /c ping localhost -n 3 > nul & del`.

T1082
System Information Discovery

Medusa Ransomware has collected data from the SMBIOS firmware table using `GetSystemFirmwareTable`.

T1083
File and Directory Discovery

Medusa Ransomware has searched for files within the victim environment for encryption and exfiltration. Medusa Ransomware has also identified files associated with remote management services.

T1106
Native API

Medusa Ransomware has leveraged Windows Native API functions to execute payloads.

T1124
System Time Discovery

Medusa Ransomware has discovered device uptime through `GetTickCount()`.

T1135
Network Share Discovery

Medusa Ransomware has identified networked drives.

T1140
Deobfuscate/Decode Files or Information

Medusa Ransomware has decoded XOR encrypted strings prior to execution in memory.

T1486
Data Encrypted for Impact

Medusa Ransomware has encrypted files using AES-256 encryption, which then appends the file extension “.medusa” to encrypted files and leaves a ransomware note named “!READ_ME_MEDUSA!!!.txt.”

T1489
Service Stop

Medusa Ransomware has the capability to terminate services related to backups, security, databases, communication, filesharing and websites. Medusa Ransomware has also utilized the `taskkill /F /IM <process> /T` command to stop targeted processes and `net stop <process>` command to stop designated services.

T1490
Inhibit System Recovery

Medusa Ransomware has deleted recovery files such as shadow copies using `vssadmin.exe`.

View all 22 procedure examples

Groups that use it1

Campaigns0

None recorded.

References4

  1. Broadcom Medusa Ransomware Medusa Group March 2025 Open source
    Threat Hunter Team Symantec and Carbon Black. (2025, March 6). Medusa Ransomware Activity Continues to Increase. Retrieved October 15, 2025.
  2. CISA Medusa Group Medusa Ransomware March 2025 Open source
    Cybersecurity and Infrastructure Security Agency. (2025, March 12). AA25-071A #StopRansomware: Medusa Ransomware. Retrieved October 15, 2025.
  3. Palo Alto Unit 42 Medusa Group Medusa Ransomware January 2024 Open source
    Anthony Galiette, Doel Santos. (2024, January 11). Medusa Ransomware Turning Your Files into Stone. Retrieved October 15, 2025.
  4. Security Scorecard Medusa Ransomware January 2024 Open source
    Vlad Pasca. (2024, January 1). A Deep Dive into Medusa Ransomware. Retrieved October 15, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.