CARDS
CARDS
Medusa is a ransomware group that emerged in June 2021, initially operating as a closed entity before transitioning to an affiliate-based Ransomware-as-a-Service (RaaS) model. While affiliates launch attacks, the core group retains control over ransom negotiations. Assessed with moderate confidence to operate from Russia or an allied state, given its avoidance of targeting organizations within Russia and the Commonwealth of Independent States, alongside its activity on Russian-language dark web forums. The group's primary motivation is financial gain, employing a multi-extortion strategy that includes data encryption, data exfiltration with threats of public release, and occasionally distributed denial-of-service (DDoS) attacks. Medusa distinguishes itself by actively using public social media channels like Telegram, Facebook, and X (formerly Twitter) under the 'OSINT Without Borders' brand to exert additional pressure on victims and publicize stolen data. This group is distinct from the older MedusaLocker ransomware variant and the Medusa mobile malware variant and is tracked by Symantec as 'Spearwing'.
This profile is generated from the same canonical actor-card record used by the Threat Actor Cards directory, so aliases, targeting fields, activity notes, and source links stay aligned as the database is enriched.
Actor Card Detail
Identity
Aliases1
Source Boundary
SOCRadar is the retained baseline for this profile. IntelliOS preserves source labels as discovery and comparison signals until a cited source explicitly supports a merge, split, or actor-boundary change.
Targeting
Associated Activity1
ATT&CK IDs1
Campaign Context
| Campaign / Operation | Source-Backed Context |
|---|---|
| medusa Ransomware / Extortion Operations4 | medusa Ransomware / Extortion Operations is retained in the campaign database for medusa. Medusa is a ransomware-as-a-service operation active since June 2021 that has targeted over 300 victims across critical infrastructure sectors including healthcare, education, legal, and manufacturing using double-extortion, with attacks surging 42% between 2023 and 2024 and a formal CISA advisory issued in early 2025. |
Indicators
SOCRadar reports 3054 IOCs for this profile. IntelliOS currently retains 15 cited public observable/context rows; this is not the full possible public-source IOC corpus.
Source coverage: 2 source groups tracked; 1 currently contributes retained observable or context rows.
Retained Observables
Showing 15 of 15
| Type | Value | Source |
|---|---|---|
| MD5 Hash | 44370f5c977e415981febf7dbb87a85c3 | CISA/FBI/MS-ISAC |
| MD5 Hash | 80d852cd199ac923205b61658a9ec5bc3 | CISA/FBI/MS-ISAC |
| Filename | !!!READ_ME_MEDUSA!!!.txt3 | CISA/FBI/MS-ISAC |
| Filename | openrdp.bat3 | CISA/FBI/MS-ISAC |
| Filename | pu.exe3 | CISA/FBI/MS-ISAC |
| Tool / Process | openrdp.bat used to allow incoming RDP and remote WMI connections3 | CISA/FBI/MS-ISAC |
| Tool / Process | pu.exe reverse shell3 | CISA/FBI/MS-ISAC |
| Email Address | key.medusa.serviceteam@protonmail.com3 | CISA/FBI/MS-ISAC |
| Email Address | mds.svt.breach@protonmail.com3 | CISA/FBI/MS-ISAC |
| Email Address | mds.svt.mir2@protonmail.com3 | CISA/FBI/MS-ISAC |
| Email Address | medusa.support@onionmail.org3 | CISA/FBI/MS-ISAC |
| Email Address | MedusaSupport@cock.li3 | CISA/FBI/MS-ISAC |
| Campaign Context | CISA states the listed Medusa email addresses were used for ransom negotiation and victim contact after compromise, not as phishing indicators.3 | CISA/FBI/MS-ISAC |
| Campaign Context | CISA, FBI, and MS-ISAC published a #StopRansomware advisory for Medusa ransomware and listed malicious files, MD5 hashes, and ransom-negotiation email addresses.3 | CISA/FBI/MS-ISAC |
| Campaign Context | IntelliOS keeps this profile scoped to Medusa ransomware and does not merge it with unrelated MedusaLocker ransomware or Medusa Android malware naming.3 | CISA/FBI/MS-ISAC |
IntelliOS Intel Products
None Found
Source Reconciliation
| Source | Primary Name | Treatment | Boundary |
|---|---|---|---|
| SOCRadar | Medusa | Baseline actor-card record retained for the current profile view. | Fields reflect the retained database record. Additional source consensus, collisions, and canonical identity mappings can be layered into this profile without automatically merging actors. |
| IntelliOS | Medusa | Normalizes this record for directory search, card display, profile lookup, and future product linking. | Normalization is a presentation and workflow aid; it is not an independent attribution claim. |
Citations
| # | Source | Use In Card |
|---|---|---|
| 1 | SOCRadar Threat Actor Database https://socradar.io/free-tools/threat-actor/ransomware | Baseline actor-card corpus source for retained profile fields. |
| 2 | SOCRadar Actor Profile https://socradar.io/free-tools/ransomware-intelligence/groups/medusa | Per-actor SOCRadar profile source for ransomware profile metadata and IOC count when available. |
| 3 | CISA/FBI/MS-ISAC: #StopRansomware Medusa Ransomware https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-071a | Government Advisory |
| 4 | medusa - Ransomware.live group profile https://www.ransomware.live/group/medusa | Ransomware.live campaign row source for medusa Ransomware / Extortion Operations. |
Source Collision Notes
IntelliOS starts this detail page from the retained source record for Medusa.
No possible same-actor, alias reuse, sub-cluster, duplicate-boundary, or external-source collision is currently retained for this actor.
| Collision Source | Candidate Records | Shared Evidence | Treatment |
|---|---|---|---|
| None retained | No candidate records | No shared evidence recorded | No collision action needed. |
| External sources | Mandiant, CrowdStrike, other non-SOCRadar sources | None retained | External collisions are shown separately when retained. |