Medusa Ransomware — Ransomware Profile

Medusa is a ransomware-as-a-service operation first identified in June 2021 that escalated sharply during 2024-2025 and remains highly active into 2026. CISA advisory AA25-071A (originally published March 12, 2025; last revised August 18, 2026) counted over 500 victims as of April 2026 across critical infrastructure sectors including medical, education, legal, insurance, technology, and manufacturing. Affiliates gain access through phishing and rapid exploitation of unpatched software, including ScreenConnect CVE-2024-1709 and Fortinet EMS CVE-2023-48788, then run double extortion via the Medusa Blog leak site with paid countdown extensions and social media pressure; demands have reportedly reached $15 million. In October 2025 Microsoft attributed zero-day exploitation of GoAnywhere MFT CVE-2025-10035 to Storm-1175, a Medusa deployer, and in April 2026 reported the actor had exploited more than 16 vulnerabilities since 2023, at times moving from initial access to encryption within 24 hours.

Also tracked as

Medusa, Frozen Spider, Spearwing, Medusa Group

IntelFusions coverage (2)

Tools & malware

Recent claimed victims

Vendor research

Countries linked to this actor

Read the full analysis on IntelFusions