Medusa Ransomware — Ransomware Profile
Medusa is a ransomware-as-a-service operation first identified in June 2021 that escalated sharply during 2024-2025 and remains highly active into 2026. CISA advisory AA25-071A (originally published March 12, 2025; last revised August 18, 2026) counted over 500 victims as of April 2026 across critical infrastructure sectors including medical, education, legal, insurance, technology, and manufacturing. Affiliates gain access through phishing and rapid exploitation of unpatched software, including ScreenConnect CVE-2024-1709 and Fortinet EMS CVE-2023-48788, then run double extortion via the Medusa Blog leak site with paid countdown extensions and social media pressure; demands have reportedly reached $15 million. In October 2025 Microsoft attributed zero-day exploitation of GoAnywhere MFT CVE-2025-10035 to Storm-1175, a Medusa deployer, and in April 2026 reported the actor had exploited more than 16 vulnerabilities since 2023, at times moving from initial access to encryption within 24 hours.Also tracked as
Medusa, Frozen Spider, Spearwing, Medusa Group
IntelFusions coverage (2)
- Exploited bugs up 34% as attackers beat the patch cycle 2026-09-03 · Vulnerabilities
- Ransomware crew Gentlemen arms affiliates with custom EDR killers 2026-06-19 · Ransomware
Tools & malware
- Advanced IP Scanner Reconnaissance
- AnyDesk Remote Access
- Atera RMM
- AVKill Defense Evasion
- Bandizip Archiving utility
- certutil LOLBin
- Cloudflare Tunnel Tunneling
- ConnectWise ScreenConnect RMM
- Impacket Post-exploitation framework
- Medusa Encryptor Ransomware
- Medusa Ransomware Ransomware
- Mesh Agent Remote Access Tool
- Mimikatz Credential Harvesting
- Navicat Database Tool
- NetScan Reconnaissance
- PDQ Deploy Deployment
- PDQ Inventory Deployment
- POORTRY Driver
- PsExec Remote Execution
- Rclone Exfiltration Tool
- RoboCopy Exfiltration
- SimpleHelp Remote Access
- SoftPerfect Network Scanner Reconnaissance
Recent claimed victims
- Comune di Battipaglia 2026-02-14
- South Hays Fire Department 2026-02-14
- Grandview Family Medicine 2026-02-14
- Balloons Everywhere 2026-02-14
- MESA Products 2026-02-14
- Resource Corporation of America 2026-01-04
- JBS 2025-12-28
- Shamrock Technologies 2025-12-19
- Callipo Group 2025-12-19
- Sampoerna Agro 2025-12-19
- Thunder Bay Counselling 2025-12-19
- Concord Academy 2025-11-30
- Universidade Municipal de São Caetano 2025-11-30
- WR Comercial 2025-11-30
- General Distributing 2025-11-21
- Nationwide Legal LLC 2025-11-21
- MFE Formwork Technology 2025-11-21
- FDC Interiors 2025-11-21
- Atrium Living Centers 2025-11-09
- Simon Property Group 2025-11-07
- Oscars Group 2025-11-07
- PT Kalimantan Prima Persada 2025-11-07
- Clackamas Community College 2025-11-07
- LaRosa’s Pizzeria 2025-11-07
- Cooperativa Esercenti Farmacia Scrl 2025-10-27
Vendor research
- Storm-1175 focuses gaze on vulnerable web-facing assets in high-tempo Medusa ransomware operations Microsoft
- Investigating active exploitation of CVE-2025-10035 GoAnywhere Managed File Transfer vulnerability Microsoft
- #StopRansomware: Medusa Ransomware (AA25-071A) CISA
- Medusa Ransomware Escalation: New Leak Site Unit 42
- Breaking Down Medusa Ransomware Armis
- Medusa Ransomware Activity Continues to Increase Symantec
- A Deep Dive into Medusa Ransomware SecurityScorecard
- Threat hunting case study: Medusa ransomware Intel471
Countries linked to this actor
- Trinidad and Tobago targets