Description Summary
Medusa ransomware (distinct from MedusaLocker and the Medusa Android botnet) is a ransomware-as-a-service that began operating in June 2021 and grew rapidly in 2023 with the launch of its 'Medusa Blog' leak site. CISA assesses Medusa affiliates have impacted more than 300 victims across multiple critical-infrastructure sectors.
Threat Actor
RaaS operators with affiliates that gain access primarily through phishing and exploitation of unpatched edge devices (Fortinet, Microsoft Exchange).
Technical Indicators
Encryption Extension
.MEDUSA
Encryption Algorithm
AES-256 (CTR mode) + RSA
Ransom Note Name
!!!READ_ME_MEDUSA!!!.txt
Targeted Industries
Medical/Healthcare, Education, Legal, Manufacturing, Insurance, Technology
First Seen
June 2021
Last Seen
Active
Geographical Location
Worldwide; heaviest in the United States
MITRE ATT&CK Matrix
| Tactic | TTP | Technique Name |
|---|---|---|
| Initial Access x 3 | T1566 | Phishing |
| T1190 | Exploit Public-Facing Application | |
| T1078 | Valid Accounts | |
| Execution x 1 | T1059 | Command and Scripting Interpreter |
| Execution Persistence x 1 | T1053 | Scheduled Task/Job |
| Defense Evasion x 2 | T1562.001 | Disable or Modify Tools |
| T1070.004 | File Deletion | |
| Discovery x 2 | T1083 | File and Directory Discovery |
| T1082 | System Information Discovery | |
| Lateral Movement x 2 | T1021.001 | Remote Services: RDP |
| T1021.002 | SMB/Windows Admin Shares | |
| Exfiltration x 2 | T1041 | Exfiltration Over C2 Channel |
| T1567.002 | Exfiltration to Cloud Storage | |
| Impact x 3 | T1486 | Data Encrypted for Impact |
| T1490 | Inhibit System Recovery | |
| T1489 | Service Stop |