ME

Medusa Ransomware

Tracked

Threat actor group tracked in the global ransomware database · Last disclosure: Feb 14, 2026

Ransomware-as-a-Service (RaaS) Double Extortion Target: Business Services
372
Total Victims
1.7% of all tracked
34
Countries Targeted
14
Sectors Targeted
2024
First Seen

ThreatAI Analysis

Compiled from the ransomware.live profile for Medusa and from this database. Figures and technique mappings are quoted from the source data, not inferred.

Medusa is a ransomware-as-a-service operation responsible for attacks on 372 victims across 34 countries, targeting sectors such as business services, healthcare, and manufacturing with double extortion tactics.

Who Medusa is

Medusa is a ransomware-as-a-service operation active since June 2021 that has targeted over 300 victims across critical infrastructure sectors including healthcare, education, legal, and manufacturing using double-extortion, with attacks surging 42% between 2023 and 2024 and a formal CISA advisory issued in early 2025.

Recorded activity

Disclosures attributed to Medusa in this database run from January 2024 to February 2026, totalling 372 victims — 1.7% of everything tracked here. Medusa has listed victims in 34 countries in this database, most often United States, followed by United Kingdom and Canada. The sectors appearing most in its listings are Business Services, Healthcare, Manufacturing.

How Medusa is documented to operate

Valid Accounts T1078 Stealth Persistence

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network.

Mitigations: Application Developer Guidance, User Training, Password Policies, User Account Management, Privileged Account Management, Multi-factor Authentication

MITRE ATT&CK reference →
External Remote Services T1133 Persistence Initial Access

Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally. Access to Valid Accounts to use the service is often a requirement, which could be obtained through credential pharming or by obtaining the credentials from users after compromising the enterprise network.

Mitigations: Limit Access to Resource Over Network, Restrict Web-Based Content, Network Segmentation, Multi-factor Authentication, Disable or Remove Feature or Program

MITRE ATT&CK reference →
Exploit Public-Facing Application T1190 Initial Access

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration. Exploited applications are often websites/web servers, but can also include databases (like SQL), standard services (like SMB or SSH), network device administration and management protocols (like SNMP and Smart Install), and any other system with Internet-accessible open sockets. On ESXi infrastructure, adversaries may exploit exposed OpenSLP services; they may alternatively exploit exposed VMware vCenter servers.

Mitigations: Vulnerability Scanning, Limit Access to Resource Over Network, Filter Network Traffic, Network Segmentation, Privileged Account Management, Application Isolation and Sandboxing

MITRE ATT&CK reference →
Phishing T1566 Initial Access

Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns. Adversaries may send victims emails containing malicious attachments or links, typically to execute malicious code on victim systems. Phishing may also be conducted via third-party services, like social media platforms.

Mitigations: Network Intrusion Prevention, Restrict Web-Based Content, User Training, Antivirus/Antimalware, Software Configuration, Audit

MITRE ATT&CK reference →
Windows Management Instrumentation T1047 Execution

Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads. WMI is designed for programmers and is the infrastructure for management data and operations on Windows systems. WMI is an administration feature that provides a uniform environment to access Windows system components. The WMI service enables both local and remote access, though the latter is facilitated by Remote Services such as Distributed Component Object Model and Windows Remote Management. Remote WMI over DCOM operates using port 135, whereas WMI over WinRM operates over port 5985 when using HTTP and 5986 for HTTPS.

Mitigations: Execution Prevention, Behavior Prevention on Endpoint, User Account Management, Privileged Account Management

MITRE ATT&CK reference →
Command and Scripting Interpreter T1059 Execution

Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell. There are also cross-platform interpreters such as Python, as well as those commonly associated with client applications such as JavaScript and Visual Basic.

Mitigations: Restrict Web-Based Content, Limit Software Installation, Execution Prevention, Code Signing, Behavior Prevention on Endpoint, Privileged Account Management

MITRE ATT&CK reference →
Software Deployment Tools T1072 Execution Lateral Movement

Adversaries may gain access to and use centralized software suites installed within an enterprise to execute commands and move laterally through the network. Configuration management and software deployment applications may be used in an enterprise network or cloud environment for routine administration purposes. These systems may also be integrated into CI/CD pipelines. Examples of such solutions include: SCCM, HBSS, Altiris, AWS Systems Manager, Microsoft Intune, Azure Arc, and GCP Deployment Manager. Access to network-wide or enterprise-wide endpoint management software may enable an adversary to achieve remote code execution on all connected systems.

Mitigations: Remote Data Storage, Limit Software Installation, User Training, Network Segmentation, Password Policies, User Account Management

MITRE ATT&CK reference →
Native API T1106 Execution

Adversaries may interact with the native OS application programming interface (API) to execute behaviors. Native APIs provide a controlled means of calling low-level OS services within the kernel, such as those involving hardware/devices, memory, and processes. These native APIs are leveraged by the OS during system boot (when other system components are not yet initialized) as well as carrying out tasks and requests during routine operations. Adversaries may abuse these OS API functions as a means of executing behaviors.

Mitigations: Execution Prevention, Behavior Prevention on Endpoint

MITRE ATT&CK reference →

MITRE ATT&CK techniques attributed to Medusa across its recorded activity. They describe the group overall, not any single incident.

Vulnerabilities Medusa is recorded exploiting

1 of these 1 are in the CISA Known Exploited Vulnerabilities catalog, 1 of them recorded by CISA as used in ransomware campaigns. CVEs attributed to Medusa in threat intelligence reporting. Patching these does not by itself rule the group out, and their presence here is not evidence of how any single organisation was reached.

Tooling observed in Medusa operations

  • Mimikatz
  • EDRSandBlast
  • KillAV
  • ThrottleStop driver
  • Advanced IP Scanner
  • Navicat
  • PDQ Inventory
  • RoboCopy
  • SoftPerfect NetScan
  • RClone
  • BITSAdmin
  • Process Explorer

Software reported in use by Medusa. Most are legitimate administration or transfer utilities; their presence in an environment is a signal to investigate, not proof of compromise.

Indicators of compromise

  • 983a20479a281a182d33b75c0945e447
  • 4fe99e5dc101170750d8ece6ea066155
  • dc344328208c3481587d0aab1005fcdd
  • 10911494fa52daee0279972f91fded01
  • 24ccd142ff83e8622f00f5443ea5cb2d
  • a6980e543efa40771ed1dcf84b29d732
  • [email protected]
  • [email protected]

Showing a sample of 18 MD5, 2 EMAIL on file. Hashes and network indicators published for Medusa. Leak-site addresses are deliberately excluded. Indicators age quickly — treat a match as a starting point for investigation, and an absence of matches as no assurance.

Threat Actor Analysis

Medusa is a ransomware threat group that has disclosed 372 victims in publicly accessible leak site data, representing 1.7% of all ransomware attacks tracked in this database. The earliest victim disclosure attributed to Medusa in our dataset dates to January 2024.

Geographically, Medusa has targeted organisations in 34 countries. The most frequently targeted nation is United States with 229 victim organisations. Other heavily targeted nations include United Kingdom, Canada, Italy.

Industry-wise, Medusa shows a concentration in the Business Services, Healthcare, Manufacturing sectors. These industries are frequently targeted because they manage sensitive data, critical operations, or have lower tolerance for operational downtime — conditions that increase ransom payment likelihood.

Like most modern ransomware operations, Medusa likely employs a double extortion model: encrypting victim files while simultaneously exfiltrating data, creating dual pressure to pay the ransom. Victim organisations that refuse payment face having their data published on the group's dark web leak site.

Note: This profile is generated from public leak site disclosures aggregated via the ransomware.live API. Data is updated automatically. The table below lists the 100 most recent of the 372 disclosures we hold for this group; use the link beneath it to page through all of them.

Recent Victim Disclosures (showing 100 of 372)

# Organization Country Sector Date
1 Balloons Everywhere balloons.com 🇺🇸 United States Consumer Services Feb 14, 2026
2 Comune di Battipaglia battipaglia.sa.it 🇮🇹 Italy Public Sector Feb 14, 2026
3 Grandview Family Medicine grandviewfamilymedicine.com 🇺🇸 United States Healthcare Feb 14, 2026
4 MESA Products mesaproducts.com 🇺🇸 United States Manufacturing Feb 14, 2026
5 South Hays Fire Department southhaysfire.com 🇺🇸 United States Public Sector Feb 14, 2026
6 Resource Corporation of America resourcecorp.com 🇺🇸 United States Healthcare Jan 4, 2026
7 JBS 🇺🇸 United States Healthcare Dec 28, 2025
8 Callipo Group callipogroup.it 🇮🇹 Italy Agriculture and Food Production Dec 19, 2025
9 Sampoerna Agro 🇮🇩 Indonesia Agriculture and Food Production Dec 19, 2025
10 Shamrock Technologies shamrocktechnologies.com 🇺🇸 United States Technology Dec 19, 2025
11 Thunder Bay Counselling thunderbaycounselling.ca 🇨🇦 Canada Public Sector Dec 19, 2025
12 Concord Academy concordacademy.org 🇺🇸 United States Education Nov 30, 2025
13 Universidade Municipal de São Caetano uscs.edu.br 🇧🇷 Brazil Education Nov 30, 2025
14 WR Comercial wrcomercial.com.br 🇧🇷 Brazil Business Services Nov 30, 2025
15 FDC Interiors fdc-interiors.com 🇦🇪 UAE Construction Nov 21, 2025
16 General Distributing generaldistributingcompany.com 🇺🇸 United States Transportation/Logistics Nov 21, 2025
17 MFE Formwork Technology mfeformwork.com 🇸🇬 Singapore Construction Nov 21, 2025
18 Nationwide Legal LLC nationwidelegal.com 🇺🇸 United States Business Services Nov 21, 2025
19 Atrium Living Centers atriumlivingcenters.com 🇺🇸 United States Healthcare Nov 9, 2025
20 Clackamas Community College 🇺🇸 United States Education Nov 7, 2025
21 LaRosa’s Pizzeria 🇺🇸 United States Hospitality and Tourism Nov 7, 2025
22 Oscars Group oscarsgroup.com.au 🇦🇺 Australia Hospitality and Tourism Nov 7, 2025
23 PT Kalimantan Prima Persada pamapersada.com 🇮🇩 Indonesia Energy Nov 7, 2025
24 Simon Property Group simon.com 🇺🇸 United States Financial Services Nov 7, 2025
25 Adore Children and Family Services adorechildren.org 🇺🇸 United States Healthcare Oct 27, 2025
26 Alissa Group alissa-group.com 🇸🇦 Saudi Arabia Agriculture and Food Production Oct 27, 2025
27 ATIRG atirg.fr 🇫🇷 France Healthcare Oct 27, 2025
28 Cooperativa Esercenti Farmacia Scrl cef.it 🇮🇹 Italy Healthcare Oct 27, 2025
29 DALCANS dalcans.fr 🇫🇷 France Consumer Services Oct 20, 2025
30 Imagicle imagicle.com 🇮🇹 Italy Technology Oct 20, 2025
31 Linxx Global Solutions linxxglobal.com 🇺🇸 United States Business Services Oct 20, 2025
32 Cemtrex cemtrex.com 🇺🇸 United States Manufacturing Oct 14, 2025
33 Design To Print printdaddy.com 🇺🇸 United States Business Services Oct 14, 2025
34 EcoPetróleo ecopetroleo.do DO Energy Oct 14, 2025
35 LA VOIE EXPRESS lavoiexpress.ma 🇲🇦 Morocco Transportation/Logistics Oct 14, 2025
36 Leprohon (Image !) Construction Oct 14, 2025
37 Lux Actuaries & Consultants luxactuaries.com 🇦🇪 UAE Financial Services Oct 8, 2025
38 CCMC ccmcnet.com 🇺🇸 United States Business Services Oct 4, 2025
39 Comcast comcast.com 🇺🇸 United States Telecommunication Oct 4, 2025
40 Future Generali futuregenerali.in 🇮🇳 India Financial Services Oct 4, 2025
41 Insightin Health insightinhealth.com 🇺🇸 United States Healthcare Oct 4, 2025
42 Leprohon leprohon.com 🇨🇦 Canada Construction Oct 4, 2025
43 LGB 🇬🇧 United Kingdom Manufacturing Oct 4, 2025
44 Organon organon.com 🇺🇸 United States Healthcare Oct 4, 2025
45 Cariri cariri.com 🇹🇹 Trinidad and Tobago Education Sep 13, 2025
46 Rad-Solutions, LLC radsolutionsllc.com 🇺🇸 United States Manufacturing Sep 8, 2025
47 Level level.com 🇺🇸 United States Financial Services Sep 3, 2025
48 TEAM GROUP teamgroup.co.th 🇹🇭 Thailand Construction Sep 3, 2025
49 Aldagi aldagi.ge GE Financial Services Aug 27, 2025
50 Expert E-commerce GmbH expert.de 🇩🇪 Germany Technology Aug 20, 2025
51 Florarte florarte.com.br 🇧🇷 Brazil Consumer Services Aug 20, 2025
52 PANSARD & ASSOCIES pansard-associes.com 🇫🇷 France Business Services Aug 6, 2025
53 Franklin Pierce Schools fpschools.org 🇺🇸 United States Education Aug 2, 2025
54 White Coffee Corporation whitecoffee.com 🇺🇸 United States Agriculture and Food Production Aug 2, 2025
55 Prosecuting Attorneys' Council of Georgia pacga.org 🇺🇸 United States Public Sector Jul 6, 2025
56 R&W Engineering rweng.com 🇺🇸 United States Manufacturing Jul 6, 2025
57 Sermo sermo.com 🇺🇸 United States Healthcare Jul 6, 2025
58 Southwest CARE Center southwestcare.org 🇺🇸 United States Healthcare Jul 6, 2025
59 Sun Direct sundirect.in 🇮🇳 India Telecommunication Jul 6, 2025
60 Bumfords bumfords.co.uk 🇬🇧 United Kingdom Consumer Services Jun 9, 2025
61 Hartwig Mechanical Inc hartwigmechanical.com 🇺🇸 United States Construction Jun 9, 2025
62 San Jose Country Club sanjosecountryclub.org 🇺🇸 United States Hospitality and Tourism Jun 9, 2025
63 Bailey's baileyscss.com 🇺🇸 United States Consumer Services Jun 1, 2025
64 Presort First Class presortfirstclass.com 🇺🇸 United States Business Services Jun 1, 2025
65 RE/MAX remax.com 🇺🇸 United States Consumer Services Jun 1, 2025
66 Town of North Providence Rhode Island corporate office northprovidenceri.gov 🇺🇸 United States Public Sector Jun 1, 2025
67 DSI Tech dsitech.com 🇺🇸 United States Technology May 18, 2025
68 DeVita & Associates, Inc. devitainc.com 🇺🇸 United States Business Services May 14, 2025
69 Nottingham Construction nottinghamconstruction.net 🇬🇧 United Kingdom Construction May 14, 2025
70 Trindel Insurance Fund trindel.org 🇺🇸 United States Financial Services May 14, 2025
71 Lake Shore Paving lakeshorepaving.com 🇺🇸 United States Construction May 9, 2025
72 Russell Child Development Center rcdc4kids.org 🇺🇸 United States Education May 9, 2025
73 Weil Construction, Inc weilconstruction.com 🇺🇸 United States Construction May 1, 2025
74 Appalachian Regional Commission arc.gov 🇺🇸 United States Public Sector Apr 27, 2025
75 Conditioned Air Corporation conditionedair.com 🇺🇸 United States Consumer Services Apr 27, 2025
76 Matthews Law matthewslaw.co.nz 🇺🇸 United States Business Services Apr 27, 2025
77 Phelps United phelpsunited.com 🇺🇸 United States Business Services Apr 27, 2025
78 Lithium Americas Nevada lithiumamericas.com 🇺🇸 United States Energy Apr 20, 2025
79 MRC de Maskinongé - district 🇨🇦 Canada Public Sector Apr 20, 2025
80 Pawnee Heights Unified School District phtigers.net 🇺🇸 United States Education Apr 16, 2025
81 Bridgebank Limited bridgebanklimited.co.uk 🇬🇧 United Kingdom Construction Apr 13, 2025
82 Fall River Public Schools fallriverschools.org 🇺🇸 United States Education Apr 13, 2025
83 McFarland Commercial Insurance Services mcfarlandinsurance.com 🇺🇸 United States Financial Services Apr 13, 2025
84 National Association for Stock Car Auto Racing nascar.com 🇺🇸 United States Hospitality and Tourism Apr 13, 2025
85 Pulse Urgent Care pulseurgentcare.com 🇺🇸 United States Healthcare Apr 13, 2025
86 FS Tool Corporation fstoolcorp.com 🇨🇦 Canada Manufacturing Apr 6, 2025
87 Krypton Solutions fstoolcorp.com 🇺🇸 United States Technology Apr 6, 2025
88 Business Software Solutions businesssoftwaresolutions.info 🇺🇸 United States Technology Mar 29, 2025
89 Family Health Services, Inc fhsi.org 🇺🇸 United States Healthcare Mar 29, 2025
90 O'Shea Builders osheabuilders.com 🇺🇸 United States Construction Mar 29, 2025
91 AutoCanada autocan.ca 🇨🇦 Canada Consumer Services Mar 23, 2025
92 Advance Tapes International 🇬🇧 United Kingdom Manufacturing Mar 22, 2025
93 Augusta Industrial Services, Inc. augustaindustrial.com 🇺🇸 United States Manufacturing Mar 20, 2025
94 Big Horn County School District #4 bgh4.org 🇺🇸 United States Education Mar 20, 2025
95 Champions Group championsgroupholdings.com 🇮🇳 India Consumer Services Mar 20, 2025
96 J McCann & Co Ltd mccann-ltd.co.uk 🇬🇧 United Kingdom Construction Mar 20, 2025
97 National Safety Council nsc.org 🇺🇸 United States Public Sector Mar 20, 2025
98 Coldwell Banker D’Ann Harper, REALTORS cbharper.com 🇺🇸 United States Business Services Mar 16, 2025
99 SRP Companies (Second lock! + Company scam!) srpcompanies.com 🇺🇸 United States Business Services Mar 16, 2025
100 Karen S Pouliot tpacpafirm.com Business Services Mar 14, 2025

Frequently Asked Questions

What is Medusa ransomware?

Medusa is a ransomware threat group that has claimed 372 victims since its first known activity in January 2024. The group operates by infiltrating target networks, exfiltrating data, encrypting files, and threatening to publish stolen data on a dark web leak site if the ransom is not paid.

How many victims has Medusa attacked?

Medusa has claimed 372 victims in our database, representing 1.7% of all tracked ransomware attacks. The most targeted countries are United States, United Kingdom, Canada, Italy.

Which countries does Medusa target?

Medusa has attacked organizations in 34 countries. The top targeted countries are: United States, United Kingdom, Canada, Italy.

Which industries does Medusa target?

Medusa most frequently targets the Business Services, Healthcare, Manufacturing sectors based on victim disclosures in our database.

Is Medusa still active?

Medusa's most recent victim disclosure in our database was on February 14, 2026. Ransomware groups frequently rebrand or go dormant; monitor this page and our ransomware map for the latest activity.