Medusa Ransomware
TrackedThreat actor group tracked in the global ransomware database · Last disclosure: Feb 14, 2026
ThreatAI Analysis
Compiled from the ransomware.live profile for Medusa and from this database. Figures and technique mappings are quoted from the source data, not inferred.
Medusa is a ransomware-as-a-service operation responsible for attacks on 372 victims across 34 countries, targeting sectors such as business services, healthcare, and manufacturing with double extortion tactics.
Who Medusa is
Medusa is a ransomware-as-a-service operation active since June 2021 that has targeted over 300 victims across critical infrastructure sectors including healthcare, education, legal, and manufacturing using double-extortion, with attacks surging 42% between 2023 and 2024 and a formal CISA advisory issued in early 2025.
Recorded activity
Disclosures attributed to Medusa in this database run from January 2024 to February 2026, totalling 372 victims — 1.7% of everything tracked here. Medusa has listed victims in 34 countries in this database, most often United States, followed by United Kingdom and Canada. The sectors appearing most in its listings are Business Services, Healthcare, Manufacturing.
How Medusa is documented to operate
Valid Accounts T1078 Stealth Persistence
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network.
Mitigations: Application Developer Guidance, User Training, Password Policies, User Account Management, Privileged Account Management, Multi-factor Authentication
MITRE ATT&CK reference →External Remote Services T1133 Persistence Initial Access
Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally. Access to Valid Accounts to use the service is often a requirement, which could be obtained through credential pharming or by obtaining the credentials from users after compromising the enterprise network.
Mitigations: Limit Access to Resource Over Network, Restrict Web-Based Content, Network Segmentation, Multi-factor Authentication, Disable or Remove Feature or Program
MITRE ATT&CK reference →Exploit Public-Facing Application T1190 Initial Access
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration. Exploited applications are often websites/web servers, but can also include databases (like SQL), standard services (like SMB or SSH), network device administration and management protocols (like SNMP and Smart Install), and any other system with Internet-accessible open sockets. On ESXi infrastructure, adversaries may exploit exposed OpenSLP services; they may alternatively exploit exposed VMware vCenter servers.
Mitigations: Vulnerability Scanning, Limit Access to Resource Over Network, Filter Network Traffic, Network Segmentation, Privileged Account Management, Application Isolation and Sandboxing
MITRE ATT&CK reference →Phishing T1566 Initial Access
Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns. Adversaries may send victims emails containing malicious attachments or links, typically to execute malicious code on victim systems. Phishing may also be conducted via third-party services, like social media platforms.
Mitigations: Network Intrusion Prevention, Restrict Web-Based Content, User Training, Antivirus/Antimalware, Software Configuration, Audit
MITRE ATT&CK reference →Windows Management Instrumentation T1047 Execution
Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads. WMI is designed for programmers and is the infrastructure for management data and operations on Windows systems. WMI is an administration feature that provides a uniform environment to access Windows system components. The WMI service enables both local and remote access, though the latter is facilitated by Remote Services such as Distributed Component Object Model and Windows Remote Management. Remote WMI over DCOM operates using port 135, whereas WMI over WinRM operates over port 5985 when using HTTP and 5986 for HTTPS.
Mitigations: Execution Prevention, Behavior Prevention on Endpoint, User Account Management, Privileged Account Management
MITRE ATT&CK reference →Command and Scripting Interpreter T1059 Execution
Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell. There are also cross-platform interpreters such as Python, as well as those commonly associated with client applications such as JavaScript and Visual Basic.
Mitigations: Restrict Web-Based Content, Limit Software Installation, Execution Prevention, Code Signing, Behavior Prevention on Endpoint, Privileged Account Management
MITRE ATT&CK reference →Software Deployment Tools T1072 Execution Lateral Movement
Adversaries may gain access to and use centralized software suites installed within an enterprise to execute commands and move laterally through the network. Configuration management and software deployment applications may be used in an enterprise network or cloud environment for routine administration purposes. These systems may also be integrated into CI/CD pipelines. Examples of such solutions include: SCCM, HBSS, Altiris, AWS Systems Manager, Microsoft Intune, Azure Arc, and GCP Deployment Manager. Access to network-wide or enterprise-wide endpoint management software may enable an adversary to achieve remote code execution on all connected systems.
Mitigations: Remote Data Storage, Limit Software Installation, User Training, Network Segmentation, Password Policies, User Account Management
MITRE ATT&CK reference →Native API T1106 Execution
Adversaries may interact with the native OS application programming interface (API) to execute behaviors. Native APIs provide a controlled means of calling low-level OS services within the kernel, such as those involving hardware/devices, memory, and processes. These native APIs are leveraged by the OS during system boot (when other system components are not yet initialized) as well as carrying out tasks and requests during routine operations. Adversaries may abuse these OS API functions as a means of executing behaviors.
Mitigations: Execution Prevention, Behavior Prevention on Endpoint
MITRE ATT&CK reference →MITRE ATT&CK techniques attributed to Medusa across its recorded activity. They describe the group overall, not any single incident.
Vulnerabilities Medusa is recorded exploiting
1 of these 1 are in the CISA Known Exploited Vulnerabilities catalog, 1 of them recorded by CISA as used in ransomware campaigns. CVEs attributed to Medusa in threat intelligence reporting. Patching these does not by itself rule the group out, and their presence here is not evidence of how any single organisation was reached.
Tooling observed in Medusa operations
- Mimikatz
- EDRSandBlast
- KillAV
- ThrottleStop driver
- Advanced IP Scanner
- Navicat
- PDQ Inventory
- RoboCopy
- SoftPerfect NetScan
- RClone
- BITSAdmin
- Process Explorer
Software reported in use by Medusa. Most are legitimate administration or transfer utilities; their presence in an environment is a signal to investigate, not proof of compromise.
Indicators of compromise
- 983a20479a281a182d33b75c0945e447
- 4fe99e5dc101170750d8ece6ea066155
- dc344328208c3481587d0aab1005fcdd
- 10911494fa52daee0279972f91fded01
- 24ccd142ff83e8622f00f5443ea5cb2d
- a6980e543efa40771ed1dcf84b29d732
- [email protected]
- [email protected]
Showing a sample of 18 MD5, 2 EMAIL on file. Hashes and network indicators published for Medusa. Leak-site addresses are deliberately excluded. Indicators age quickly — treat a match as a starting point for investigation, and an absence of matches as no assurance.
Threat Actor Analysis
Medusa is a ransomware threat group that has disclosed 372 victims in publicly accessible leak site data, representing 1.7% of all ransomware attacks tracked in this database. The earliest victim disclosure attributed to Medusa in our dataset dates to January 2024.
Geographically, Medusa has targeted organisations in 34 countries. The most frequently targeted nation is United States with 229 victim organisations. Other heavily targeted nations include United Kingdom, Canada, Italy.
Industry-wise, Medusa shows a concentration in the Business Services, Healthcare, Manufacturing sectors. These industries are frequently targeted because they manage sensitive data, critical operations, or have lower tolerance for operational downtime — conditions that increase ransom payment likelihood.
Like most modern ransomware operations, Medusa likely employs a double extortion model: encrypting victim files while simultaneously exfiltrating data, creating dual pressure to pay the ransom. Victim organisations that refuse payment face having their data published on the group's dark web leak site.
Note: This profile is generated from public leak site disclosures aggregated via the ransomware.live API. Data is updated automatically. The table below lists the 100 most recent of the 372 disclosures we hold for this group; use the link beneath it to page through all of them.
Recent Victim Disclosures (showing 100 of 372)
| # | Organization | Country | Sector | Date |
|---|---|---|---|---|
| 1 | Balloons Everywhere balloons.com | 🇺🇸 United States | Consumer Services | Feb 14, 2026 |
| 2 | Comune di Battipaglia battipaglia.sa.it | 🇮🇹 Italy | Public Sector | Feb 14, 2026 |
| 3 | Grandview Family Medicine grandviewfamilymedicine.com | 🇺🇸 United States | Healthcare | Feb 14, 2026 |
| 4 | MESA Products mesaproducts.com | 🇺🇸 United States | Manufacturing | Feb 14, 2026 |
| 5 | South Hays Fire Department southhaysfire.com | 🇺🇸 United States | Public Sector | Feb 14, 2026 |
| 6 | Resource Corporation of America resourcecorp.com | 🇺🇸 United States | Healthcare | Jan 4, 2026 |
| 7 | JBS | 🇺🇸 United States | Healthcare | Dec 28, 2025 |
| 8 | Callipo Group callipogroup.it | 🇮🇹 Italy | Agriculture and Food Production | Dec 19, 2025 |
| 9 | Sampoerna Agro | 🇮🇩 Indonesia | Agriculture and Food Production | Dec 19, 2025 |
| 10 | Shamrock Technologies shamrocktechnologies.com | 🇺🇸 United States | Technology | Dec 19, 2025 |
| 11 | Thunder Bay Counselling thunderbaycounselling.ca | 🇨🇦 Canada | Public Sector | Dec 19, 2025 |
| 12 | Concord Academy concordacademy.org | 🇺🇸 United States | Education | Nov 30, 2025 |
| 13 | Universidade Municipal de São Caetano uscs.edu.br | 🇧🇷 Brazil | Education | Nov 30, 2025 |
| 14 | WR Comercial wrcomercial.com.br | 🇧🇷 Brazil | Business Services | Nov 30, 2025 |
| 15 | FDC Interiors fdc-interiors.com | 🇦🇪 UAE | Construction | Nov 21, 2025 |
| 16 | General Distributing generaldistributingcompany.com | 🇺🇸 United States | Transportation/Logistics | Nov 21, 2025 |
| 17 | MFE Formwork Technology mfeformwork.com | 🇸🇬 Singapore | Construction | Nov 21, 2025 |
| 18 | Nationwide Legal LLC nationwidelegal.com | 🇺🇸 United States | Business Services | Nov 21, 2025 |
| 19 | Atrium Living Centers atriumlivingcenters.com | 🇺🇸 United States | Healthcare | Nov 9, 2025 |
| 20 | Clackamas Community College | 🇺🇸 United States | Education | Nov 7, 2025 |
| 21 | LaRosa’s Pizzeria | 🇺🇸 United States | Hospitality and Tourism | Nov 7, 2025 |
| 22 | Oscars Group oscarsgroup.com.au | 🇦🇺 Australia | Hospitality and Tourism | Nov 7, 2025 |
| 23 | PT Kalimantan Prima Persada pamapersada.com | 🇮🇩 Indonesia | Energy | Nov 7, 2025 |
| 24 | Simon Property Group simon.com | 🇺🇸 United States | Financial Services | Nov 7, 2025 |
| 25 | Adore Children and Family Services adorechildren.org | 🇺🇸 United States | Healthcare | Oct 27, 2025 |
| 26 | Alissa Group alissa-group.com | 🇸🇦 Saudi Arabia | Agriculture and Food Production | Oct 27, 2025 |
| 27 | ATIRG atirg.fr | 🇫🇷 France | Healthcare | Oct 27, 2025 |
| 28 | Cooperativa Esercenti Farmacia Scrl cef.it | 🇮🇹 Italy | Healthcare | Oct 27, 2025 |
| 29 | DALCANS dalcans.fr | 🇫🇷 France | Consumer Services | Oct 20, 2025 |
| 30 | Imagicle imagicle.com | 🇮🇹 Italy | Technology | Oct 20, 2025 |
| 31 | Linxx Global Solutions linxxglobal.com | 🇺🇸 United States | Business Services | Oct 20, 2025 |
| 32 | Cemtrex cemtrex.com | 🇺🇸 United States | Manufacturing | Oct 14, 2025 |
| 33 | Design To Print printdaddy.com | 🇺🇸 United States | Business Services | Oct 14, 2025 |
| 34 | EcoPetróleo ecopetroleo.do | DO | Energy | Oct 14, 2025 |
| 35 | LA VOIE EXPRESS lavoiexpress.ma | 🇲🇦 Morocco | Transportation/Logistics | Oct 14, 2025 |
| 36 | Leprohon (Image !) | — | Construction | Oct 14, 2025 |
| 37 | Lux Actuaries & Consultants luxactuaries.com | 🇦🇪 UAE | Financial Services | Oct 8, 2025 |
| 38 | CCMC ccmcnet.com | 🇺🇸 United States | Business Services | Oct 4, 2025 |
| 39 | Comcast comcast.com | 🇺🇸 United States | Telecommunication | Oct 4, 2025 |
| 40 | Future Generali futuregenerali.in | 🇮🇳 India | Financial Services | Oct 4, 2025 |
| 41 | Insightin Health insightinhealth.com | 🇺🇸 United States | Healthcare | Oct 4, 2025 |
| 42 | Leprohon leprohon.com | 🇨🇦 Canada | Construction | Oct 4, 2025 |
| 43 | LGB | 🇬🇧 United Kingdom | Manufacturing | Oct 4, 2025 |
| 44 | Organon organon.com | 🇺🇸 United States | Healthcare | Oct 4, 2025 |
| 45 | Cariri cariri.com | 🇹🇹 Trinidad and Tobago | Education | Sep 13, 2025 |
| 46 | Rad-Solutions, LLC radsolutionsllc.com | 🇺🇸 United States | Manufacturing | Sep 8, 2025 |
| 47 | Level level.com | 🇺🇸 United States | Financial Services | Sep 3, 2025 |
| 48 | TEAM GROUP teamgroup.co.th | 🇹🇭 Thailand | Construction | Sep 3, 2025 |
| 49 | Aldagi aldagi.ge | GE | Financial Services | Aug 27, 2025 |
| 50 | Expert E-commerce GmbH expert.de | 🇩🇪 Germany | Technology | Aug 20, 2025 |
| 51 | Florarte florarte.com.br | 🇧🇷 Brazil | Consumer Services | Aug 20, 2025 |
| 52 | PANSARD & ASSOCIES pansard-associes.com | 🇫🇷 France | Business Services | Aug 6, 2025 |
| 53 | Franklin Pierce Schools fpschools.org | 🇺🇸 United States | Education | Aug 2, 2025 |
| 54 | White Coffee Corporation whitecoffee.com | 🇺🇸 United States | Agriculture and Food Production | Aug 2, 2025 |
| 55 | Prosecuting Attorneys' Council of Georgia pacga.org | 🇺🇸 United States | Public Sector | Jul 6, 2025 |
| 56 | R&W Engineering rweng.com | 🇺🇸 United States | Manufacturing | Jul 6, 2025 |
| 57 | Sermo sermo.com | 🇺🇸 United States | Healthcare | Jul 6, 2025 |
| 58 | Southwest CARE Center southwestcare.org | 🇺🇸 United States | Healthcare | Jul 6, 2025 |
| 59 | Sun Direct sundirect.in | 🇮🇳 India | Telecommunication | Jul 6, 2025 |
| 60 | Bumfords bumfords.co.uk | 🇬🇧 United Kingdom | Consumer Services | Jun 9, 2025 |
| 61 | Hartwig Mechanical Inc hartwigmechanical.com | 🇺🇸 United States | Construction | Jun 9, 2025 |
| 62 | San Jose Country Club sanjosecountryclub.org | 🇺🇸 United States | Hospitality and Tourism | Jun 9, 2025 |
| 63 | Bailey's baileyscss.com | 🇺🇸 United States | Consumer Services | Jun 1, 2025 |
| 64 | Presort First Class presortfirstclass.com | 🇺🇸 United States | Business Services | Jun 1, 2025 |
| 65 | RE/MAX remax.com | 🇺🇸 United States | Consumer Services | Jun 1, 2025 |
| 66 | Town of North Providence Rhode Island corporate office northprovidenceri.gov | 🇺🇸 United States | Public Sector | Jun 1, 2025 |
| 67 | DSI Tech dsitech.com | 🇺🇸 United States | Technology | May 18, 2025 |
| 68 | DeVita & Associates, Inc. devitainc.com | 🇺🇸 United States | Business Services | May 14, 2025 |
| 69 | Nottingham Construction nottinghamconstruction.net | 🇬🇧 United Kingdom | Construction | May 14, 2025 |
| 70 | Trindel Insurance Fund trindel.org | 🇺🇸 United States | Financial Services | May 14, 2025 |
| 71 | Lake Shore Paving lakeshorepaving.com | 🇺🇸 United States | Construction | May 9, 2025 |
| 72 | Russell Child Development Center rcdc4kids.org | 🇺🇸 United States | Education | May 9, 2025 |
| 73 | Weil Construction, Inc weilconstruction.com | 🇺🇸 United States | Construction | May 1, 2025 |
| 74 | Appalachian Regional Commission arc.gov | 🇺🇸 United States | Public Sector | Apr 27, 2025 |
| 75 | Conditioned Air Corporation conditionedair.com | 🇺🇸 United States | Consumer Services | Apr 27, 2025 |
| 76 | Matthews Law matthewslaw.co.nz | 🇺🇸 United States | Business Services | Apr 27, 2025 |
| 77 | Phelps United phelpsunited.com | 🇺🇸 United States | Business Services | Apr 27, 2025 |
| 78 | Lithium Americas Nevada lithiumamericas.com | 🇺🇸 United States | Energy | Apr 20, 2025 |
| 79 | MRC de Maskinongé - district | 🇨🇦 Canada | Public Sector | Apr 20, 2025 |
| 80 | Pawnee Heights Unified School District phtigers.net | 🇺🇸 United States | Education | Apr 16, 2025 |
| 81 | Bridgebank Limited bridgebanklimited.co.uk | 🇬🇧 United Kingdom | Construction | Apr 13, 2025 |
| 82 | Fall River Public Schools fallriverschools.org | 🇺🇸 United States | Education | Apr 13, 2025 |
| 83 | McFarland Commercial Insurance Services mcfarlandinsurance.com | 🇺🇸 United States | Financial Services | Apr 13, 2025 |
| 84 | National Association for Stock Car Auto Racing nascar.com | 🇺🇸 United States | Hospitality and Tourism | Apr 13, 2025 |
| 85 | Pulse Urgent Care pulseurgentcare.com | 🇺🇸 United States | Healthcare | Apr 13, 2025 |
| 86 | FS Tool Corporation fstoolcorp.com | 🇨🇦 Canada | Manufacturing | Apr 6, 2025 |
| 87 | Krypton Solutions fstoolcorp.com | 🇺🇸 United States | Technology | Apr 6, 2025 |
| 88 | Business Software Solutions businesssoftwaresolutions.info | 🇺🇸 United States | Technology | Mar 29, 2025 |
| 89 | Family Health Services, Inc fhsi.org | 🇺🇸 United States | Healthcare | Mar 29, 2025 |
| 90 | O'Shea Builders osheabuilders.com | 🇺🇸 United States | Construction | Mar 29, 2025 |
| 91 | AutoCanada autocan.ca | 🇨🇦 Canada | Consumer Services | Mar 23, 2025 |
| 92 | Advance Tapes International | 🇬🇧 United Kingdom | Manufacturing | Mar 22, 2025 |
| 93 | Augusta Industrial Services, Inc. augustaindustrial.com | 🇺🇸 United States | Manufacturing | Mar 20, 2025 |
| 94 | Big Horn County School District #4 bgh4.org | 🇺🇸 United States | Education | Mar 20, 2025 |
| 95 | Champions Group championsgroupholdings.com | 🇮🇳 India | Consumer Services | Mar 20, 2025 |
| 96 | J McCann & Co Ltd mccann-ltd.co.uk | 🇬🇧 United Kingdom | Construction | Mar 20, 2025 |
| 97 | National Safety Council nsc.org | 🇺🇸 United States | Public Sector | Mar 20, 2025 |
| 98 | Coldwell Banker D’Ann Harper, REALTORS cbharper.com | 🇺🇸 United States | Business Services | Mar 16, 2025 |
| 99 | SRP Companies (Second lock! + Company scam!) srpcompanies.com | 🇺🇸 United States | Business Services | Mar 16, 2025 |
| 100 | Karen S Pouliot tpacpafirm.com | — | Business Services | Mar 14, 2025 |
Frequently Asked Questions
What is Medusa ransomware?
Medusa is a ransomware threat group that has claimed 372 victims since its first known activity in January 2024. The group operates by infiltrating target networks, exfiltrating data, encrypting files, and threatening to publish stolen data on a dark web leak site if the ransom is not paid.
How many victims has Medusa attacked?
Medusa has claimed 372 victims in our database, representing 1.7% of all tracked ransomware attacks. The most targeted countries are United States, United Kingdom, Canada, Italy.
Which countries does Medusa target?
Medusa has attacked organizations in 34 countries. The top targeted countries are: United States, United Kingdom, Canada, Italy.
Which industries does Medusa target?
Medusa most frequently targets the Business Services, Healthcare, Manufacturing sectors based on victim disclosures in our database.
Is Medusa still active?
Medusa's most recent victim disclosure in our database was on February 14, 2026. Ransomware groups frequently rebrand or go dormant; monitor this page and our ransomware map for the latest activity.