Medusa is a name used for multiple unrelated malware families, most notably an Android banking trojan and a separate ransomware operation. The Android Medusa is a banking trojan that abuses Android Accessibility Services to monitor user interface events, log keystrokes, collect active-window content and metadata, intercept notifications, and execute scripted on-device actions. Its operators can use accessibility-driven commands to navigate apps, interact with interface elements, alter focused input fields, replace clipboard contents, capture screenshots, and support limited remote-control functionality. The malware has been associated with automated transfer system activity, credential theft, and fraud against banking and cryptocurrency applications, with campaigns assessed to have targeted users primarily in the United States, Canada, and Turkey. Reporting has linked the Android operation to a Turkish-speaking actor and an operator panel referred to as Ankatras. Distribution has been observed through Android malware delivery ecosystems including smishing-linked infrastructure and malicious dropper applications.
Separately, Medusa is also an established ransomware family first observed in 2019 and later associated with a dedicated leak site and double-extortion activity. The ransomware operation has been linked to intrusions against sectors including finance, healthcare, and professional services in the United States, Australia, and the United Kingdom. Recent reporting also ties the Medusa ransomware ecosystem to the financially motivated actor Storm-1175, which historically exploited newly disclosed vulnerabilities in internet-facing systems, moved rapidly to data theft and encryption, and later shifted to a newer ransomware variant. Because the same name refers to distinct malware families with materially different platforms and behaviors, Medusa should be disambiguated carefully in operational use.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
22 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In the recent campaign, according to Microsoft, the group may be exploiting CVE-2026-18577 - a flaw in the N-central, a remote monitoring and management (RMM) console used by various service providers to supervise client endpoints. The flaw allows threat actors “unauthenticated, ‘god-mode’ access,” warned cybersecurity firm Huntress.
Storm-1175 is the name assigned to a China-based threat actor with a history of deploying Medusa ransomware after exploiting security flaws in Fortinet FortiClient EMS (CVE-2023-48788). | The use of StormEncryptor marks a shift from the adversary's previous use of Medusa ransomware... Storm-1175 is the name assigned to a China-based threat actor with a history of deploying Medusa ransomware after exploiting security flaws...
Storm-1175 is the name assigned to a China-based threat actor with a history of deploying Medusa ransomware after exploiting security flaws in Mirth Connect (CVE-2023-37679, CVE-2023-43208). | The use of StormEncryptor marks a shift from the adversary's previous use of Medusa ransomware... Storm-1175 is the name assigned to a China-based threat actor with a history of deploying Medusa ransomware after exploiting security flaws...
In an analysis published in October 2025, Microsoft also attributed the threat actor to the exploitation of a critical security vulnerability impacting Fortra GoAnywhere (CVE-2025-10035) to facilitate the deployment of Medusa ransomware. | The use of StormEncryptor marks a shift from the adversary's previous use of Medusa ransomware... Storm-1175 is the name assigned to a China-based threat actor with a history of deploying Medusa ransomware after exploiting security flaws...
Storm-1175 is the name assigned to a China-based threat actor with a history of deploying Medusa ransomware after exploiting security flaws in JetBrains TeamCity (CVE-2024-27198, CVE-2024-27199). | The use of StormEncryptor marks a shift from the adversary's previous use of Medusa ransomware... Storm-1175 is the name assigned to a China-based threat actor with a history of deploying Medusa ransomware after exploiting security flaws...
Storm-1175 is the name assigned to a China-based threat actor with a history of deploying Medusa ransomware after exploiting security flaws in ConnectWise ScreenConnect (CVE-2024-1709, CVE-2024-1708). | The use of StormEncryptor marks a shift from the adversary's previous use of Medusa ransomware... Storm-1175 is the name assigned to a China-based threat actor with a history of deploying Medusa ransomware after exploiting security flaws...
Storm-1175 is the name assigned to a China-based threat actor with a history of deploying Medusa ransomware after exploiting security flaws in JetBrains TeamCity (CVE-2024-27198, CVE-2024-27199). | The use of StormEncryptor marks a shift from the adversary's previous use of Medusa ransomware... Storm-1175 is the name assigned to a China-based threat actor with a history of deploying Medusa ransomware after exploiting security flaws...
Storm-1175 is the name assigned to a China-based threat actor with a history of deploying Medusa ransomware after exploiting security flaws in Mirth Connect (CVE-2023-37679, CVE-2023-43208). | The use of StormEncryptor marks a shift from the adversary's previous use of Medusa ransomware... Storm-1175 is the name assigned to a China-based threat actor with a history of deploying Medusa ransomware after exploiting security flaws...
Storm-1175 is the name assigned to a China-based threat actor with a history of deploying Medusa ransomware after exploiting security flaws in ConnectWise ScreenConnect (CVE-2024-1709, CVE-2024-1708). | The use of StormEncryptor marks a shift from the adversary's previous use of Medusa ransomware... Storm-1175 is the name assigned to a China-based threat actor with a history of deploying Medusa ransomware after exploiting security flaws...
CVE-2024-57728 (CVSS: 7.2): This vulnerability permits admin users to upload arbitrary files anywhere on the SimpleHelp file system by exploiting a crafted zip file, known as a zip slip. This could lead to arbitrary code execution on the host system in the context of the SimpleHelp server user. | Since 6 February 2025, S-RM has responded to several incidents involving the ransomware group Medusa, where this group has exploited SimpleHelp vulnerabilities to gain initial access to victims’ infrastructure.
CVE-2024-57727 (CVSS: 7.5): This flaw involves multiple path traversal vulnerabilities, permitting unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. | Since 6 February 2025, S-RM has responded to several incidents involving the ransomware group Medusa, where this group has exploited SimpleHelp vulnerabilities to gain initial access to victims’ infrastructure.
In the first quarter of 2025, Medusa ransomware operators launched a wave of coordinated attacks against UK organisations through compromised MSPs. | The campaigns, uncovered in early 2025, leveraged a trio of flaws—CVE-2024-57726, CVE-2024-57727, and CVE-2024-57728—to pivot from compromised RMM servers into victim networks with “minimal friction.”
This method was observed in high-tempo operations linked to Medusa affiliates (Storm-1175) and has been adopted by multiple groups deploying Akira and Black Basta payloads.
...the Microsoft Exchange Server deserialization of untrusted data bug, tracked as CVE-2023-21529, was included to the CISA list after being leveraged by Chinese financially motivated threat operation Storm-1175 to spread the Medusa ransomware. | the Microsoft Exchange Server deserialization of untrusted data bug, tracked as CVE-2023-21529, was included to the CISA list after being leveraged by Chinese financially motivated threat operation Storm-1175 to spread the Medusa ransomware.
The flaw in question is CVE-2023-0669, an SQL injection vulnerability that allows remote code execution without authentication. Discovered in February 2023, Fortra released an immediate patch, but attackers continue to exploit it months later. Medusa, an emerging ransomware-as-a-service (RaaS) group... | Medusa, an emerging ransomware-as-a-service (RaaS) group, has been targeting vulnerable Fortra's GoAnywhere MFT systems... Medusa scans the internet for exposed GoAnywhere servers, injecting malicious payloads to encrypt and exfiltrate data.
A notorious group of hackers is currently causing major disruption globally by deploying the devastating Medusa ransomware. | This pace was clear during a recent attack on a SAP NetWeaver system (tracked as CVE-2025-31324). The flaw was announced on April 24, 2025, and by April 25, the group was already using it to launch Medusa ransomware operations.
Storm-1175 actors are running up-tempo campaigns to deliver Medusa ransomware... Attackers move quickly from vulnerability exploitation to data exfiltration and, finally, delivery of Medusa ransomware, often within a few days and, in some cases, within 24 hours. | Storm-1175 has rapidly exploited more than a dozen known vulnerabilities or N-days, the most recent of which is CVE-2026-1731, a critical remote code execution flaw in BeyondTrust Remote Support and older versions of the vendor's Privileged Remote Access (PRA). The vulnerability was initially disclosed Feb. 6 and quickly came under attack, with the Cybersecurity and Infrastructure Security Agency (CISA) adding it to the Known Exploited Vulnerabilities (KEV) catalog a week later.
Storm-1175 actors are running up-tempo campaigns to deliver Medusa ransomware... Attackers move quickly from vulnerability exploitation to data exfiltration and, finally, delivery of Medusa ransomware, often within a few days and, in some cases, within 24 hours. | Other notable flaws exploited by Storm-1175 include CVE-2025-31161, a critical authentication bypass vulnerability in CrushFTP's file transfer software that also sparked a public disclosure dispute last spring.
The most recent example is CVE-2026-23760, a critical authentication bypass vulnerability in SmarterMail that was exploited by various threat groups, including the China-linked Storm-2603. | Storm-1175 actors are running up-tempo campaigns to deliver Medusa ransomware... Attackers move quickly from vulnerability exploitation to data exfiltration and, finally, delivery of Medusa ransomware, often within a few days and, in some cases, within 24 hours.
A notorious group of hackers is currently causing major disruption globally by deploying the devastating Medusa ransomware.
China-based actor Storm-1175 runs fast ransomware attacks, exploiting new flaws to breach systems and quickly deploy Medusa ransomware. | Since 2023, Microsoft Threat Intelligence has observed exploitation of over 16 vulnerabilities, including: CVE-2025-52691 and CVE-2026-23760 (SmarterMail)
China-based actor Storm-1175 runs fast ransomware attacks, exploiting new flaws to breach systems and quickly deploy Medusa ransomware. | Since 2023, Microsoft Threat Intelligence has observed exploitation of over 16 vulnerabilities, including: CVE-2023-46805 and CVE-2024-21887 (Ivanti Connect Secure and Policy Secure)
14 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
UNC3886 has used the publicly available rootkits REPTILE and MEDUSA.
Medusa Ransomware has the capability to detect security solutions for termination or deletion within the victim device using hard-coded lists of strings containing security product executables.
In recent months, the Lazarus Group and its related intrusion set Moonstone Sleet have also been attributed to attacks targeting South Korean and Middle East entities with Qilin and Medusa ransomware.
In recent months, the Lazarus Group and its related intrusion set Moonstone Sleet have also been attributed to attacks targeting South Korean and Middle East entities with Qilin and Medusa ransomware.
Название «Mythic» в имени кластера отражает использование Mythic C2 - открытого фреймворка для post-exploitation с множеством агентов (Apollo, Medusa, Athena).
38 distinct techniques documented for this family, organized by ATT&CK tactic.
The vulnerability is assessed to be a patch bypass for CVE-2026-18556, both of which allow authentication bypass and account takeover in susceptible versions.
Medusa Locker has been known to exploit Remote Desktop Protocol (RDP) vulnerabilities to gain access to a victim’s machine
Storm-1175 is known for fast ransomware campaigns that exploit newly disclosed vulnerabilities before organizations can patch them.
Authors of Medusa also implemented a simple but powerful scripting engine that is able to execute a sequence of commands on the infected device.
Execution - PowerShell (T1059.001). Внутри архива LNK-файл, который через powershell.exe запускает base64-закодированный скрипт.
Looking at ransomware brands in our dataset from 2020 to 2025, three brands (LockBit, Medusa, Phobos) and one technique (abuse of native BitLocker encryption) have persisted for the duration.
The attackers also chain multiple exploits to achieve deeper access, such as remote code execution.
Now we have a primitive for obtaining write-access to a trusted process’s files. The next step is to weaponize it. This will involve backdooring the .pyc files themselves.
Dynamic Linker Hijacking occurs when an attacker manipulates the linking process to redirect execution flow. This can involve altering the library search order through LD_PRELOAD, modifying configuration files like /etc/ld.so.conf, or tampering with cached library mappings in /etc/ld.so.cache.
The vulnerability is assessed to be a patch bypass for CVE-2026-18556, both of which allow authentication bypass and account takeover in susceptible versions.
The Gentlemen’s developers are systematically reverse-engineering samples from other groups, such as Babuk, Qilin, LockBit 5.0 and Medusa, to select the strongest encryption routines, code-obfuscation techniques and EDR evasion methods to incorporate into their own codebase.
The vulnerability is assessed to be a patch bypass for CVE-2026-18556, both of which allow authentication bypass and account takeover in susceptible versions.
Agent Tesla has used ProcessWindowStyle.Hidden to hide windows. APT-C-36 has set the ShowWindow property of the Win32_ProcessStartup object to zero to hide PowerShell execution. APT19 used -W Hidden to conceal PowerShell windows by setting the WindowStyle parameter to hidden.
Now we have a primitive for obtaining write-access to a trusted process’s files. The next step is to weaponize it. This will involve backdooring the .pyc files themselves.
Dynamic Linker Hijacking occurs when an attacker manipulates the linking process to redirect execution flow. This can involve altering the library search order through LD_PRELOAD, modifying configuration files like /etc/ld.so.conf, or tampering with cached library mappings in /etc/ld.so.cache.
This feature allows the actors to collect much more than only user input, as it can also track actions performed on the UI and visualize the content shown in the applications. This enables the attackers to gain further insights into victim’s behavior and grants them ability to steal credentials without having to resort to the use of phishing attacks.
Keylogger Medusa authors implemented a simple accessibility-based keylogging, allowing the bot to get access to UI events, such as clicks, text inputs and focus events of all application on the infected device.
Medusa starts to recursively collect the information about the active window starting from the root node.
With a special command from C2 Medusa starts to recursively collect the information about the active window starting from the root node. Information of interest is such as but not limited to: node bounds in screen coordinates, text of the node, whether this node is categorized as password.
This feature allows the actors to collect much more than only user input, as it can also track actions performed on the UI and visualize the content shown in the applications. This enables the attackers to gain further insights into victim’s behavior and grants them ability to steal credentials without having to resort to the use of phishing attacks.
Keylogger Medusa authors implemented a simple accessibility-based keylogging, allowing the bot to get access to UI events, such as clicks, text inputs and focus events of all application on the infected device.
Storm-1175 has also been observed rapidly moving from initial access to data exfiltration and ransomware deployment, mostly within a few days
Combined with the media streaming feature, this provides the attackers with limited but powerful RAT functionalities that allow them to interact with the infected device while monitoring them at the same time... scrshot_key Performs TAKE_SCREENSHOT global action
if ( p7e1b9eb1 . isInterceptingNotif ( ) ) { p53cba4f5 . sendToC2 ( "LOG,NOTIF," + title + ": " + text , Boolean . valueOf ( true ) ) ; this . cancelNotification ( sbn . getKey ( ) ) ; }
All these botnets use two separate C2 backends to manage bots. The first is the fronting C2, to which bots connect to, while the second is the actual bot operator panel, used by operators to manage their different botnets.
97 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware family named as claiming responsibility for an extensive Comcast breach.
Previously used ransomware family that Storm-1175 appears to have replaced with StormEncryptor in its latest attacks.
Named ransomware associated here only through a claimed responsibility for the ACRO incident; the claim was not verified in the content.
Ransomware previously deployed by the same threat actors against finance, healthcare, and professional services organizations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.