FORENSIA

THREAT_ACTOR · G1051

Medusa Group

Also known as: Medusa Group

Profile

Medusa Group has been active since at least 2021 and was initially operated as a closed ransomware group before evolving into a Ransomware-as-a-Service (RaaS) operation. Some reporting indicates that certain attacks may still be conducted directly by the ransomware’s core developers. Public sources have also referred to the group as “Spearwing” or “Medusa Actors.” Medusa Group employs living-off-the-land techniques, frequently leveraging publicly available tools and common remote management software to conduct operations. The group engages in double extortion tactics, exfiltrating data prior to encryption and threatening to publish stolen information if ransom demands are not met. For initial access, Medusa Group has exploited publicly known vulnerabilities, conducted phishing campaigns, and used credentials or access purchased from Initial Access Brokers (IABs). The group is opportunistic and has targeted a wide range of sectors globally.

MITRE ATT&CK ↗

Techniques

57 ATT&CK techniques attributed to this actor.

T1003.001 LSASS MemoryT1003.003 NTDST1016 System Network Configuration DiscoveryT1018 Remote System DiscoveryT1021.001 Remote Desktop ProtocolT1027.002 Software PackingT1027.010 Command ObfuscationT1033 System Owner/User DiscoveryT1046 Network Service DiscoveryT1047 Windows Management InstrumentationT1057 Process DiscoveryT1059.001 PowerShellT1059.003 Windows Command ShellT1069.002 Domain GroupsT1070.003 Clear Command HistoryT1070.004 File DeletionT1071.001 Web ProtocolsT1072 Software Deployment ToolsT1078 Valid AccountsT1082 System Information DiscoveryT1083 File and Directory DiscoveryT1087.001 Local AccountT1090.003 Multi-hop ProxyT1105 Ingress Tool TransferT1106 Native APIT1112 Modify RegistryT1135 Network Share DiscoveryT1136.002 Domain AccountT1190 Exploit Public-Facing ApplicationT1218.014 MMCT1219 Remote Access ToolsT1486 Data Encrypted for ImpactT1489 Service StopT1490 Inhibit System RecoveryT1505.003 Web ShellT1518.001 Security Software DiscoveryT1529 System Shutdown/RebootT1543.003 Windows ServiceT1548.002 Bypass User Account ControlT1553.002 Code SigningT1559.001 Component Object ModelT1564.003 Hidden WindowT1567.002 Exfiltration to Cloud StorageT1569.002 Service ExecutionT1570 Lateral Tool TransferT1573.002 Asymmetric CryptographyT1583.006 Web ServicesT1585.001 Social Media AccountsT1585.002 Email AccountsT1588.002 ToolT1608.002 Upload ToolT1650 Acquire AccessT1652 Device Driver DiscoveryT1657 Financial TheftT1685 Disable or Modify ToolsT1686 Disable or Modify System FirewallT1690 Prevent Command History Logging

Software

5 malware/tools attributed to this actor.

MimikatzPsExeccertutilRcloneMedusa Ransomware

Related corpus activity

10,209 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to Medusa Group.

IndicatorTypeFamilySevSrc
cve-2023-44976cveransomware852
cve-2026-1969cve851
cve-2025-68670cve852
cve-2026-3102cve853
cve-2025-34117cve851
cve-2021-29441cve851
cve-2026-22584cve852
cve-2025-11837cve852
cve-2025-34054cve854
cve-2014-2321cve851
cve-2020-22653cve852
cve-2025-2492cve852
cve-2017-18377cve851
cve-2021-25646cve851
cve-2025-66478cve852
cve-2025-0921cve852
cve-2021-27076cve851
cve-2013-3307cve852
cve-2016-5681cve852
cve-2016-15047cve854
cve-2024-1781cve851
cve-2018-8007cve851
cve-2021-4045cve851
cve-2020-17456cve851
cve-2022-47945cve851
cve-2020-22658cve852
cve-2025-23304cve852
cve-2026-4368cveransomware851
cve-2013-7471cve851
cve-2026-0740cve851

Showing the top 30 by severity of 10,209.