Medusa Ransomware — Malware Profile
Medusa Ransomware has been utilized in attacks since at least 2021. Medusa Ransomware has been known to be utilized in conjunction with living off the land techniques and remote management software. Medusa Ransomware has been used in campaigns associated with “double extortion” ransomware activity, where data is exfiltrated from victim environments prior to encryption, with threats to publish files if a ransom is not paid. Medusa Ransomware software was initially a closed ransomware variant which later evolved to a Ransomware as a Service (RaaS). Medusa Ransomware has impacted victims from a diverse range of sectors within a multitude of countries, and it is assessed Medusa Ransomware is used in an opportunistic manner.
MITRE ATT&CK techniques (22)
- T1007 System Service Discovery
- T1027.013 Encrypted/Encoded File
- T1057 Process Discovery
- T1059.001 PowerShell
- T1059.003 Windows Command Shell
- T1070.004 File Deletion
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1106 Native API
- T1124 System Time Discovery
- T1135 Network Share Discovery
- T1140 Deobfuscate/Decode Files or Information
- T1486 Data Encrypted for Impact
- T1489 Service Stop
- T1490 Inhibit System Recovery
- T1518.001 Security Software Discovery
- T1543.003 Windows Service
- T1559 Inter-Process Communication
- T1564.003 Hidden Window
- T1679 Selective Exclusion
- T1680 Local Storage Discovery
- T1685 Disable or Modify Tools