Spearwing is a cybercrime group associated with operating the Medusa ransomware-as-a-service (RaaS) program since 2023. The group is widely linked to a commercially run extortion platform in which affiliates deploy the Medusa encryptor in exchange for a share of ransom proceeds. Medusa operations attributed to Spearwing have been described as using double-extortion tactics, combining data theft with file encryption and pressure through a leak site. Spearwing-linked Medusa activity has targeted organizations across multiple sectors, including healthcare, financial services, government, and non-profit entities. Reported tradecraft includes exploitation of unpatched public-facing applications, especially Microsoft Exchange, as well as use of hijacked legitimate accounts and possible initial access broker access. Post-compromise behavior associated with Medusa intrusions includes use of remote administration and deployment tools, credential dumping, network reconnaissance, lateral movement, data exfiltration, and efforts to disable security products. Observed Medusa intrusion patterns include frequent use of legitimate remote management and administrative tooling, deployment orchestration through PDQ Deploy, exfiltration with tools such as Rclone, and Bring Your Own Vulnerable Driver techniques to impair endpoint defenses. Spearwing-linked operations have also been noted for relatively consistent tactics, techniques, and procedures across incidents, which is somewhat atypical for a broad affiliate ecosystem and may indicate either tightly standardized playbooks or substantial operator involvement by the core group. Spearwing is distinct from the MedusaLocker operation despite the similar naming. Reporting has also tied Medusa deployments to affiliates outside traditional cybercrime circles, including activity assessed as involving North Korea-linked Lazarus operators acting as Medusa affiliates rather than Spearwing itself being a state actor. Spearwing is best characterized as a financially motivated ransomware and extortion actor centered on the Medusa RaaS ecosystem.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
16 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
13 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Attributed as the cybercrime group behind the Medusa ransomware-as-a-service platform and builder toolkit used by an affiliate in this intrusion.
Described as the cybercrime group behind the Medusa ransomware-as-a-service platform, providing the ransomware builder/toolkit used by an affiliate intrusion attributed here to Lazarus.
Cybercrime group operating the Medusa ransomware-as-a-service program, enabling affiliates to conduct extortion attacks across multiple sectors including healthcare and non-profits.
Cybercrime group assessed to operate the Medusa RaaS program, recruiting affiliates to deploy the Medusa encryptor and conduct double-extortion ransomware operations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.