01
Medusa is tracked as an affiliate-enabled ransomware service.1
The brand supplies shared capabilities, but affiliates can change access methods and tooling; incident scoping should follow observed behavior rather than assume one fixed playbook.
CARDS
Medusa is a ransomware group that emerged in June 2021, initially operating as a closed entity before transitioning to an affiliate-based Ransomware-as-a-Service (RaaS) model. While affiliates launch attacks, the core group retains control over ransom negotiations. Assessed with moderate confidence to operate from Russia or an allied state, given its avoidance of targeting organizations within Russia and the Commonwealth of Independent States, alongside its activity on Russian-language dark web forums. The group's primary motivation is financial gain, employing a multi-extortion strategy that includes data encryption, data exfiltration with threats of public release, and occasionally distributed denial-of-service (DDoS) attacks. Medusa distinguishes itself by actively using public social media channels like Telegram, Facebook, and X (formerly Twitter) under the 'OSINT Without Borders' brand to exert additional pressure on victims and publicize stolen data. This group is distinct from the older MedusaLocker ransomware variant and the Medusa mobile malware variant and is tracked by Symantec as 'Spearwing'.
Directory Briefing
01
The brand supplies shared capabilities, but affiliates can change access methods and tooling; incident scoping should follow observed behavior rather than assume one fixed playbook.
02
The retained behavior points to credentials, remote access, phishing, or exposed services; preserve authentication, VPN, edge-device, email, and remote-administration evidence together.
03
Check for earlier credential use, remote sessions, administrative changes, and data access because public actor records often understate the full pre-impact timeline.
04
Evidence includes credential or account abuse; response should cover privileged, service, remote-access, SaaS, and recovery identities—not just interactive user passwords.
05
Lateral movement, administrative access, and shared server infrastructure can turn a limited foothold into broad business interruption.
06
Reported tooling or behavior includes PowerShell, remote execution, or other dual-use administration behavior; detection must distinguish authorized administration from anomalous context and sequence.
07
Defense impairment or evidence removal is retained in the source record. Protect immutable backups and investigate access to recovery systems before trusting them.
08
Collection or exfiltration behavior includes data staging and exfiltration; counsel and forensics need a shared record of what was accessed, staged, and transferred.
09
Retained targeting includes Construction of Buildings, Food Manufacturing, Other Information Services, Credit Unions, and Software Publishers across United Arab Emirates, Antigua and Barbuda, Armenia, and Angola; translate those sectors into the organization's exposed systems and high-value data.
10
Align counsel, forensics, identity, recovery, insurance, communications, and regulatory analysis around one compromise timeline and one evidence-preservation plan.
Bottom Line Up Front
The brand supplies shared capabilities, but affiliates can change access methods and tooling; incident scoping should follow observed behavior rather than assume one fixed playbook.
The retained behavior points to credentials, remote access, phishing, or exposed services; preserve authentication, VPN, edge-device, email, and remote-administration evidence together.
Check for earlier credential use, remote sessions, administrative changes, and data access because public actor records often understate the full pre-impact timeline.
Evidence includes credential or account abuse; response should cover privileged, service, remote-access, SaaS, and recovery identities—not just interactive user passwords.
Lateral movement, administrative access, and shared server infrastructure can turn a limited foothold into broad business interruption.
Reported tooling or behavior includes PowerShell, remote execution, or other dual-use administration behavior; detection must distinguish authorized administration from anomalous context and sequence.
Defense impairment or evidence removal is retained in the source record. Protect immutable backups and investigate access to recovery systems before trusting them.
Collection or exfiltration behavior includes data staging and exfiltration; counsel and forensics need a shared record of what was accessed, staged, and transferred.
Retained targeting includes Construction of Buildings, Food Manufacturing, Other Information Services, Credit Unions, and Software Publishers across United Arab Emirates, Antigua and Barbuda, Armenia, and Angola; translate those sectors into the organization's exposed systems and high-value data.
Align counsel, forensics, identity, recovery, insurance, communications, and regulatory analysis around one compromise timeline and one evidence-preservation plan.
Decision Context
Medusa is a ransomware group that emerged in June 2021, initially operating as a closed entity before transitioning to an affiliate-based Ransomware-as-a-Service (RaaS) model. While affiliates launch attacks, the core group retains control over ransom negotiations. Assessed with moderate confidence to operate from Russia or an allied state, given its avoidance of targeting organizations within Russia and the Commonwealth of Independent States, alongside its activity on Russian-language dark web forums. The group's primary motivation is financial gain, employing a multi-extortion strategy that includes data encryption, data exfiltration with threats of public release, and occasionally distributed denial-of-service (DDoS) attacks. Medusa distinguishes itself by actively using public social media channels like Telegram, Facebook, and X (formerly Twitter) under the 'OSINT Without Borders' brand to exert additional pressure on victims and publicize stolen data. This group is distinct from the older MedusaLocker ransomware variant and the Medusa mobile malware variant and is tracked by Symantec as 'Spearwing'.1,2
Actor Card Detail
Victimology
No named victim organizations are retained in the cited source artifacts for this profile. Countries and sectors are targeting context, not victim identities.
Identity
Aliases1
Source Boundary
SOCRadar is the retained baseline for this profile. IntelliOS preserves source labels as discovery and comparison signals until a cited source explicitly supports a merge, split, or actor-boundary change.
Targeting
Target Countries / Exposure1,2
Associated Activity1
ATT&CK IDs1
Campaign Context
| Campaign / Operation | Source-Backed Context |
|---|---|
| medusa Ransomware / Extortion Operations4 | medusa Ransomware / Extortion Operations is retained in the campaign database for medusa. Medusa is a ransomware-as-a-service operation active since June 2021 that has targeted over 300 victims across critical infrastructure sectors including healthcare, education, legal, and manufacturing using double-extortion, with attacks surging 42% between 2023 and 2024 and a formal CISA advisory issued in early 2025. |
Indicators
SOCRadar reports 3054 IOCs for this profile. IntelliOS currently retains 15 cited public observable/context rows; this is not the full possible public-source IOC corpus.
Source coverage: 2 source groups tracked; 1 currently contributes retained observable or context rows.
Retained Observables
Showing 15 of 15
| Type | Value | Source |
|---|---|---|
| MD5 Hash | 44370f5c977e415981febf7dbb87a85c3 | CISA/FBI/MS-ISAC |
| MD5 Hash | 80d852cd199ac923205b61658a9ec5bc3 | CISA/FBI/MS-ISAC |
| Filename | !!!READ_ME_MEDUSA!!!.txt3 | CISA/FBI/MS-ISAC |
| Filename | openrdp.bat3 | CISA/FBI/MS-ISAC |
| Filename | pu.exe3 | CISA/FBI/MS-ISAC |
| Tool / Process | openrdp.bat used to allow incoming RDP and remote WMI connections3 | CISA/FBI/MS-ISAC |
| Tool / Process | pu.exe reverse shell3 | CISA/FBI/MS-ISAC |
| Email Address | key.medusa.serviceteam@protonmail.com3 | CISA/FBI/MS-ISAC |
| Email Address | mds.svt.breach@protonmail.com3 | CISA/FBI/MS-ISAC |
| Email Address | mds.svt.mir2@protonmail.com3 | CISA/FBI/MS-ISAC |
| Email Address | medusa.support@onionmail.org3 | CISA/FBI/MS-ISAC |
| Email Address | MedusaSupport@cock.li3 | CISA/FBI/MS-ISAC |
| Campaign Context | CISA states the listed Medusa email addresses were used for ransom negotiation and victim contact after compromise, not as phishing indicators.3 | CISA/FBI/MS-ISAC |
| Campaign Context | CISA, FBI, and MS-ISAC published a #StopRansomware advisory for Medusa ransomware and listed malicious files, MD5 hashes, and ransom-negotiation email addresses.3 | CISA/FBI/MS-ISAC |
| Campaign Context | IntelliOS keeps this profile scoped to Medusa ransomware and does not merge it with unrelated MedusaLocker ransomware or Medusa Android malware naming.3 | CISA/FBI/MS-ISAC |
Actor Chronology
No source-backed actor-activity dates are currently retained. Publication and record-maintenance dates are not promoted into activity dates.
IntelliOS Intel Products
Source Reconciliation
| Source | Primary Name | Treatment | Boundary |
|---|---|---|---|
| SOCRadar | Medusa | Baseline actor-card record retained for the current profile view. | Fields reflect the retained database record. Additional source consensus, collisions, and canonical identity mappings can be layered into this profile without automatically merging actors. |
| IntelliOS | Medusa | Normalizes this record for directory search, card display, profile lookup, and future product linking. | Normalization is a presentation and workflow aid; it is not an independent attribution claim. |
Source Collision Notes
IntelliOS starts this detail page from the retained source record for Medusa.
No possible same-actor, alias reuse, sub-cluster, duplicate-boundary, or external-source collision is currently retained for this actor.
| Collision Source | Candidate Records | Shared Evidence | Treatment |
|---|---|---|---|
| None retained | No candidate records | No shared evidence recorded | No collision action needed. |
| External sources | Mandiant, CrowdStrike, other non-SOCRadar sources | None retained | External collisions are shown separately when retained. |
Citations
| # | Source | Use In Card |
|---|---|---|
| 1 | SOCRadar Threat Actor Database https://socradar.io/free-tools/threat-actor/ransomware | Threat actor directory source for profile fields and reported activity. |
| 2 | SOCRadar Actor Profile https://socradar.io/free-tools/ransomware-intelligence/groups/medusa | Actor-specific source for ransomware profile metadata and reported IOC counts when available. |
| 3 | CISA/FBI/MS-ISAC: #StopRansomware Medusa Ransomware https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-071a | Government Advisory |
| 4 | medusa - Ransomware.live group profile https://www.ransomware.live/group/medusa | Ransomware.live campaign row source for medusa Ransomware / Extortion Operations. |