{"id":488,"count":0,"description":"<div class=\"actor-dossier\" style=\"display:flex;flex-wrap:wrap;gap:12px;margin-bottom:20px\">\n  <div style=\"flex:1;min-width:160px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Year Established<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">2021<\/div>\n  <\/div>\n  <div style=\"flex:1;min-width:160px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Attribution<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">Unknown (Eastern European Suspected)<\/div>\n  <\/div>\n  <div style=\"flex:1;min-width:160px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Motivation<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">Financial<\/div>\n  <\/div>\n  <div style=\"flex:2;min-width:200px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Modus Operandi (MO)<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">Double-extortion RaaS, education and healthcare targeting, public countdown timers<\/div>\n  <\/div>\n  <div style=\"flex:2;min-width:200px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Primary Aliases<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">Medusa, MedusaLocker (distinct group)<\/div>\n  <\/div>\n<\/div>\n<p>Medusa Ransomware is a Ransomware-as-a-Service (RaaS) operation that emerged in 2021 and significantly escalated its activity from 2023 onwards, becoming one of the more prolific ransomware threats globally. Note that Medusa Ransomware is distinct from the older MedusaLocker ransomware family, despite the similar name ,  they represent different threat actor groups with different toolsets and operational approaches.<\/p>\n<p>Medusa operates a sophisticated double-extortion model, combining file encryption with data exfiltration and a public-facing data leak site (the \"Medusa Blog\") where victim data is threatened with publication. A distinctive feature of Medusa's extortion methodology is the use of public countdown timers on their leak site ,  victims can see exactly how much time remains before their stolen data is published, creating intense psychological pressure to pay the ransom quickly.<\/p>\n<p>The group has demonstrated a troubling willingness to target schools and healthcare facilities, sectors where data sensitivity and operational disruption create maximum leverage for ransom extraction. Notable victims include Minneapolis Public Schools, whose sensitive student and staff data ,  including records of abuse allegations ,  was published in full after the district refused to pay a $1 million ransom demand.<\/p>\n<p>Medusa recruits affiliates through underground forums and offers ransom negotiation services, technical support, and customisable ransomware payloads. Their initial access methods include exploitation of unpatched vulnerabilities in public-facing services, phishing campaigns, and purchasing access from initial access brokers operating in criminal marketplaces.<\/p>\n\n<p><strong>Tactical Telemetry and Extortion Framework:<\/strong> In confirmed intrusions, <strong>Medusa Ransomware<\/strong> employs double-extortion tactics, combining high-speed asymmetric encryption with automated data exfiltration pipelines. Initial access is routinely obtained via compromised Remote Desktop Protocol (RDP) credentials, initial access broker (IAB) marketplaces, and spear-phishing campaigns delivering infostealer payloads. Organizations operating critical IT infrastructure are advised to enforce strict network segmentation, deploy hardware-backed multi-factor authentication across all external access points, and maintain immutable offline backups to mitigate operational disruption.<\/p>","link":"https:\/\/cyberasia.io\/actor\/medusa-ransomware\/","name":"Medusa Ransomware","slug":"medusa-ransomware","taxonomy":"threat_actor","parent":0,"meta":[],"_links":{"self":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/threat_actors\/488","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/threat_actors"}],"about":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/taxonomies\/threat_actor"}],"wp:post_type":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/posts?threat_actors=488"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}