🔴 [LATEST] 313 TEAM TARGETS AL RAJHI BANK AND SAUDI CIVIL DEFENSE, SITES UNREACHABLE FROM DOZENS OF LOCATIONS    ◆    🔴 [LATEST] DDOS QATAR INVESTMENT AUTHORITY: 1 CRITICAL SOVEREIGN WEB PORTAL DOWN    ◆    🔴 [LATEST] RIPPERSEC TARGETS ISRAEL CART: 1 CRITICAL E-COMMERCE PLATFORM DISRUPTED    ◆    🔴 [LATEST] US NAVY DDOS ATTACK: 3 CRITICAL MILITARY PORTALS DISRUPTED    ◆    🔴 [LATEST] QATAR LIVING DDOS ATTACK: 1 CRITICAL EXPATRIATE PORTAL DISRUPTED

> CLASSIFIED_DOSSIER :: THREAT_ACTOR_PROFILE

Flag
MEDUSA RANSOMWARE

/actor/medusa-ransomware/  ·  0 intel reports

Year Established
2021
Attribution
Unknown (Eastern European Suspected)
Motivation
Financial
Modus Operandi (MO)
Double-extortion RaaS, education and healthcare targeting, public countdown timers
Primary Aliases
Medusa, MedusaLocker (distinct group)

Medusa Ransomware is a Ransomware-as-a-Service (RaaS) operation that emerged in 2021 and significantly escalated its activity from 2023 onwards, becoming one of the more prolific ransomware threats globally. Note that Medusa Ransomware is distinct from the older MedusaLocker ransomware family, despite the similar name , they represent different threat actor groups with different toolsets and operational approaches.

Medusa operates a sophisticated double-extortion model, combining file encryption with data exfiltration and a public-facing data leak site (the "Medusa Blog") where victim data is threatened with publication. A distinctive feature of Medusa's extortion methodology is the use of public countdown timers on their leak site , victims can see exactly how much time remains before their stolen data is published, creating intense psychological pressure to pay the ransom quickly.

The group has demonstrated a troubling willingness to target schools and healthcare facilities, sectors where data sensitivity and operational disruption create maximum leverage for ransom extraction. Notable victims include Minneapolis Public Schools, whose sensitive student and staff data , including records of abuse allegations , was published in full after the district refused to pay a $1 million ransom demand.

Medusa recruits affiliates through underground forums and offers ransom negotiation services, technical support, and customisable ransomware payloads. Their initial access methods include exploitation of unpatched vulnerabilities in public-facing services, phishing campaigns, and purchasing access from initial access brokers operating in criminal marketplaces.

Tactical Telemetry and Extortion Framework: In confirmed intrusions, Medusa Ransomware employs double-extortion tactics, combining high-speed asymmetric encryption with automated data exfiltration pipelines. Initial access is routinely obtained via compromised Remote Desktop Protocol (RDP) credentials, initial access broker (IAB) marketplaces, and spear-phishing campaigns delivering infostealer payloads. Organizations operating critical IT infrastructure are advised to enforce strict network segmentation, deploy hardware-backed multi-factor authentication across all external access points, and maintain immutable offline backups to mitigate operational disruption.

STATUS: ACTIVE CLASSIFICATION: RANSOMWARE SYNDICATE LAST SEEN: Unknown

> LINKED_INTEL_REPORTS (0)

[NULL] No intel reports found for this actor.

> cd ../articles