Medusa Ransomware — Ransomware Profile

Medusa is a ransomware-as-a-service operation first identified in June 2021 that escalated sharply during 2024-2025 and remains highly active into 2026. CISA advisory AA25-071A (March 12, 2025) counted over 300 victims across critical infrastructure sectors including healthcare, education, legal, insurance, technology, and manufacturing. Affiliates gain access through phishing and rapid exploitation of unpatched software, including ScreenConnect CVE-2024-1709 and Fortinet EMS CVE-2023-48788, then run double extortion via the Medusa Blog leak site with paid countdown extensions and social media pressure; demands have reportedly reached $15 million. In October 2025 Microsoft attributed zero-day exploitation of GoAnywhere MFT CVE-2025-10035 to Storm-1175, a Medusa deployer, and in April 2026 reported the actor had exploited more than 16 vulnerabilities since 2023, at times moving from initial access to encryption within 24 hours.

Also tracked as

Medusa, Frozen Spider

Tools & malware

Recent claimed victims

Vendor research

Read the full analysis on IntelFusions