Medusa is a ransomware-as-a-service operation active since at least 2021. It is known for targeting organizations through exploitation of vulnerable public-facing services and remote management infrastructure, then using stolen access for persistence, credential theft, lateral movement, data exfiltration, and ransomware deployment. The group has been associated with leak-site extortion and has been observed claiming victims across multiple sectors, including industrial and critical infrastructure environments. Medusa has repeatedly used vulnerability exploitation for initial access. Documented tradecraft includes exploitation of CVE-2023-48788 in FortiClient Enterprise Management Server to achieve remote code execution, establish persistence through remote management tooling, create local administrative access, dump LSASS credentials, move laterally, exfiltrate data, and deploy ransomware. The group has also exploited chained SimpleHelp vulnerabilities, notably CVE-2024-57727 and CVE-2024-57728, to compromise SimpleHelp servers, hijack managed agents, redirect them to attacker-controlled infrastructure, and expand access across victim networks. Reporting also links Medusa to exploitation of public-facing applications more broadly, including SQL injection paths. Observed post-compromise behavior includes use of remote access and management software for persistence, offline cracking of stolen password hashes, credential dumping, system and user discovery, security software discovery, lateral movement, and deployment tooling to distribute ransomware across the environment. Medusa has been observed using PowerShell, DNS-based command-and-control patterns, hidden-window execution, and attempts to bypass User Account Control through COM-based methods. The group also performs defense evasion by identifying security products for termination or deletion. Medusa operates an extortion model centered on data theft and public shaming via a leak site, and has been described as a ransomware-as-a-service group with affiliates. It has been among the more active ransomware actors in recent reporting periods and has been cited as capable of targeting organizations tied to major public events as well as enterprise and public-sector environments. Known aliases include Medusa Blog, Medusa ransomware, Medusa ransomware gang, and Medusa affiliates.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
58 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 malware families attributed to this actor across reporting.
4 additional families tracked in Mallory.
15 CVEs this actor has used in observed campaigns. 15 of them exploited in the wild.
Medusa Group has also utilized ... CVE-2023-48788 in Fortinet EMS for initial access to victim environments.
Medusa Group has also utilized CVE-2024-1709 in ScreenConnect ... for initial access to victim environments.
CVE-2024-57727 (CVSS: 7.5): This flaw involves multiple path traversal vulnerabilities, permitting unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests.
CVE-2024-57728 (CVSS: 7.2): This vulnerability permits admin users to upload arbitrary files anywhere on the SimpleHelp file system by exploiting a crafted zip file, known as a zip slip. This could lead to arbitrary code execution on the host system in the context of the SimpleHelp server user.
The deserialization vulnerability, tracked as CVE-2025-10035, "allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection," Fortra said... CISA ... warning that it was being actively used in ransomware campaigns.
10 more CVEs tied to this actor tracked in Mallory.
65 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Claimed responsibility for the ACRO intrusion after disclosure, but the article states attribution remains unconfirmed and the claim may have been fabricated for publicity.
Referenced as a ransomware operation previously linked by researchers to North Korean state-sponsored actors.
Listed as a threat actor associated with the generic installation exploitation analytic, but no campaign-specific activity is described in this reference.
Listed as one of many threat actors associated with the detection's ATT&CK-style annotations for PowerShell and DNS TXT command-and-control behavior; no specific campaign or activity is described in this reference.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.