Medusa is a financially motivated ransomware family and ransomware-as-a-service operation first identified in 2021 that became increasingly active in 2023. It is distinct from MedusaLocker, the Medusa Android banking trojan, and the open-source Medusa authentication-cracking tool. Its Windows encryptor is written in Visual C++. The operation uses double extortion, combining file encryption with theft of sensitive information and threats to publish or sell that information. Victims span multiple countries and industries, including healthcare, education, manufacturing, finance, technology, government, and professional services, with substantial activity against United States organizations.
Affiliates obtain access through phishing and spearphishing, compromised remote-access accounts, initial access brokers, and exploitation of vulnerable internet-facing systems. Medusa intrusions have involved FortiClient EMS vulnerability CVE-2023-48788 and Citrix NetScaler vulnerability CVE-2023-4966. Microsoft tracks Storm-1175 as an actor associated with Medusa ransomware operations and has identified it exploiting GoAnywhere MFT vulnerability CVE-2025-10035.
Following compromise, operators perform network discovery, dump credentials from LSASS and Active Directory, and use compromised administrative accounts for lateral movement. They abuse PowerShell, WMI, SMB, RDP, PsExec, and legitimate management products such as PDQ Deploy, ConnectWise, AnyDesk, and SimpleHelp for remote execution, payload distribution, persistent access, and concealment within administrative activity. Medusa attacks also employ vulnerable drivers and tools such as AuKill to disable endpoint protection.
The ransomware encrypts files using cryptography incorporating RSA, places ransom notes in affected directories, terminates security and backup services, and deletes volume shadow copies to obstruct recovery. Operators exfiltrate victim data and apply payment pressure through Tor-based negotiation and leak sites, public countdowns, and social-media channels. Restoring encrypted systems does not eliminate the confidentiality risks associated with stolen data.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
20 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Medusa gains access to a target system through a known weakness such as the Fortinet EMS SQL injection vulnerability. CVE-2023-48788 impacts environments that have FortiClient EMS, versions 7.2 to 7.2.2 and 7.0.1 to 7.0.10, installed to manage endpoints.
Reporting associates activity with CVE-2024-1709 (ConnectWise ScreenConnect auth bypass). Exposure and patch status should be validated before treating it as confirmed Medusa exploitation.
CVE-2023-4966: CitrixBleed (August to October 2023) ... The above-mentioned CVEs are confirmed to be exploited by Medusa Group from various security incident reports.
Group Member “nopiro” had used CVE-2022–26134 Exploit (Confluence ONGL Injection) for Medusa Ransomware Operations. | The leak consists of Chat Transcript between group members from December 11 2022 to March 2023.
Deux nouveaux CVE exploités : ... CVE-2026-1731 : injection de commandes OS dans BeyondTrust (CWE-78) ... Weaponisation en moins de 24h après annonce publique d’un CVE, parfois jusqu’à une semaine avant la divulgation publique | Medusa est une opération ransomware-as-a-service (RaaS) active depuis juin 2021, ayant impacté plus de 500 organisations d’infrastructure critique...
Deux nouveaux CVE exploités : CVE-2025-10035 : désérialisation de données non fiables dans Fortra GoAnywhere (CWE-502) ... Weaponisation en moins de 24h après annonce publique d’un CVE, parfois jusqu’à une semaine avant la divulgation publique | Medusa est une opération ransomware-as-a-service (RaaS) active depuis juin 2021, ayant impacté plus de 500 organisations d’infrastructure critique...
In the recent campaign, according to Microsoft, the group may be exploiting CVE-2026-18577 - a flaw in the N-central, a remote monitoring and management (RMM) console used by various service providers to supervise client endpoints. The flaw allows threat actors “unauthenticated, ‘god-mode’ access,” warned cybersecurity firm Huntress.
Storm-1175 is the name assigned to a China-based threat actor with a history of deploying Medusa ransomware after exploiting security flaws in Mirth Connect (CVE-2023-37679, CVE-2023-43208). | The use of StormEncryptor marks a shift from the adversary's previous use of Medusa ransomware... Storm-1175 is the name assigned to a China-based threat actor with a history of deploying Medusa ransomware after exploiting security flaws...
Storm-1175 is the name assigned to a China-based threat actor with a history of deploying Medusa ransomware after exploiting security flaws in JetBrains TeamCity (CVE-2024-27198, CVE-2024-27199). | The use of StormEncryptor marks a shift from the adversary's previous use of Medusa ransomware... Storm-1175 is the name assigned to a China-based threat actor with a history of deploying Medusa ransomware after exploiting security flaws...
Storm-1175 is the name assigned to a China-based threat actor with a history of deploying Medusa ransomware after exploiting security flaws in ConnectWise ScreenConnect (CVE-2024-1709, CVE-2024-1708). | The use of StormEncryptor marks a shift from the adversary's previous use of Medusa ransomware... Storm-1175 is the name assigned to a China-based threat actor with a history of deploying Medusa ransomware after exploiting security flaws...
Storm-1175 is the name assigned to a China-based threat actor with a history of deploying Medusa ransomware after exploiting security flaws in JetBrains TeamCity (CVE-2024-27198, CVE-2024-27199). | The use of StormEncryptor marks a shift from the adversary's previous use of Medusa ransomware... Storm-1175 is the name assigned to a China-based threat actor with a history of deploying Medusa ransomware after exploiting security flaws...
Storm-1175 is the name assigned to a China-based threat actor with a history of deploying Medusa ransomware after exploiting security flaws in Mirth Connect (CVE-2023-37679, CVE-2023-43208). | The use of StormEncryptor marks a shift from the adversary's previous use of Medusa ransomware... Storm-1175 is the name assigned to a China-based threat actor with a history of deploying Medusa ransomware after exploiting security flaws...
CVE-2024-57728 (CVSS: 7.2): This vulnerability permits admin users to upload arbitrary files anywhere on the SimpleHelp file system by exploiting a crafted zip file, known as a zip slip. This could lead to arbitrary code execution on the host system in the context of the SimpleHelp server user. | Since 6 February 2025, S-RM has responded to several incidents involving the ransomware group Medusa, where this group has exploited SimpleHelp vulnerabilities to gain initial access to victims’ infrastructure.
CVE-2024-57727 (CVSS: 7.5): This flaw involves multiple path traversal vulnerabilities, permitting unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. | Since 6 February 2025, S-RM has responded to several incidents involving the ransomware group Medusa, where this group has exploited SimpleHelp vulnerabilities to gain initial access to victims’ infrastructure.
In the first quarter of 2025, Medusa ransomware operators launched a wave of coordinated attacks against UK organisations through compromised MSPs. | The campaigns, uncovered in early 2025, leveraged a trio of flaws—CVE-2024-57726, CVE-2024-57727, and CVE-2024-57728—to pivot from compromised RMM servers into victim networks with “minimal friction.”
This method was observed in high-tempo operations linked to Medusa affiliates (Storm-1175) and has been adopted by multiple groups deploying Akira and Black Basta payloads.
...the Microsoft Exchange Server deserialization of untrusted data bug, tracked as CVE-2023-21529, was included to the CISA list after being leveraged by Chinese financially motivated threat operation Storm-1175 to spread the Medusa ransomware. | the Microsoft Exchange Server deserialization of untrusted data bug, tracked as CVE-2023-21529, was included to the CISA list after being leveraged by Chinese financially motivated threat operation Storm-1175 to spread the Medusa ransomware.
The flaw in question is CVE-2023-0669, an SQL injection vulnerability that allows remote code execution without authentication. Discovered in February 2023, Fortra released an immediate patch, but attackers continue to exploit it months later. Medusa, an emerging ransomware-as-a-service (RaaS) group... | Medusa, an emerging ransomware-as-a-service (RaaS) group, has been targeting vulnerable Fortra's GoAnywhere MFT systems... Medusa scans the internet for exposed GoAnywhere servers, injecting malicious payloads to encrypt and exfiltrate data.
A notorious group of hackers is currently causing major disruption globally by deploying the devastating Medusa ransomware. | This pace was clear during a recent attack on a SAP NetWeaver system (tracked as CVE-2025-31324). The flaw was announced on April 24, 2025, and by April 25, the group was already using it to launch Medusa ransomware operations.
Storm-1175 actors are running up-tempo campaigns to deliver Medusa ransomware... Attackers move quickly from vulnerability exploitation to data exfiltration and, finally, delivery of Medusa ransomware, often within a few days and, in some cases, within 24 hours. | Other notable flaws exploited by Storm-1175 include CVE-2025-31161, a critical authentication bypass vulnerability in CrushFTP's file transfer software that also sparked a public disclosure dispute last spring.
13 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
After that, Darktrace observed the attacker encrypting files and appending them with the extension “.MEDUSA” while also dropping a ransom note with the file name “!!!Read_me_Medusa!!!.txt”
Storm-1175 (tracked by Microsoft Threat Intelligence) is actively exploiting this vulnerability. The group is associated with Medusa ransomware operations and is known for targeting public-facing applications for initial access.
Droppers using the same instal*tvtap*.apk naming convention were previously identified as distributing Medusa banking trojan samples, attributed by Cleafy in 2024 to the UNKN affiliate botnet.
Medusa is a ransomware-as-a-service platform that has operated since June 2021 and targets critical infrastructure.
На скомпрометированных управляющих Linux-хостах злоумышленники разворачивали набор инструментов для длительного доступа к инфраструктуре жертв. В него входили руткиты Medusa и REPTILE.
In recent months, the Lazarus Group and its related intrusion set Moonstone Sleet have also been attributed to attacks targeting South Korean and Middle East entities with Qilin and Medusa ransomware.
33 distinct techniques documented for this family, organized by ATT&CK tactic.
182 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware mentioned as background context for prior attacks involving SimpleHelp. No ransomware-specific behavior or distribution details are provided.
Le loader inclut des restrictions de ciblage (pas de pays CIS, pas de secteur public), pratique courante dans les malwares du nexus russe (LockBit, Qilin, Cl0p, Medusa).
Mentioned as an example of Russia- or CIS-associated ransomware using CIS-targeting exclusion checks; no operational association with Sauron Loader is established.
Banking trojan mentioned solely because researchers identified a tentative, unconfirmed link between RemControl operator UNKK and a Medusa affiliate.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.