HackerFeeds
All ransomware groups

medusa

517 tracked victims
·first seen 2023-01-11·last activity 2026-02-13

Group profile

Medusa is a ransomware-as-a-service operation active since June 2021 that has targeted over 300 victims across critical infrastructure sectors including healthcare, education, legal, and manufacturing using double-extortion, with attacks surging 42% between 2023 and 2024 and a formal CISA advisory issued in early 2025.

MITRE ATT&CK TTPs

TA0001

Initial Access

  • T1078Valid Accounts

    Initial access through brute force or compromised credentials of legitimate RDP accounts.

  • T1133External Remote Services

    Accesses the victim's network via an RDP service.

  • T1566Phishing

    Initial access through phishing email attachments.

TA0002

Execution

  • T1047Windows Management Instrumentation

    Uses a series of Windows commands, such as bcdedit.exe and vssadmin.

  • T1059Command and Scripting Interpreter

    Uses a series of Windows commands, such as bcdedit.exe and vssadmin.

TA0005

Defense Evasion

  • T1562Impair Defenses

    Employs Windows Management Instrumentation (WMIC) command-line to delete shadow copies.

  • T1562.001Disable or Modify Tools

    Terminates services or processes related to antivirus/security tools.

  • T1562.009Safe Mode Boot

    Abuses Safe Mode to evade endpoint detection.

TA0006

Credential Access

  • T1110Brute Force

    Uses brute force on local RDP account passwords.

TA0007

Discovery

  • T1083File and Directory Discovery

    Queries specified files, folders, and file extensions.

  • T1135Network Share Discovery

    Enumerates network shares.

TA0008

Lateral Movement

  • T1021Remote Services

    Uses remote services for login and lateral movement via RDP and SMB.

TA0010

Exfiltration

  • T1045Exfiltration Over C2 Channel

    Transfers data to attacker-controlled servers via an existing command-and-control (C2) channel.

  • T1048Exfiltration Over Alternative Protocol

    Exfiltrates data using alternative protocols, such as FTP/SFTP, to avoid detection by traditional methods.

  • T1567Exfiltration Over Web Service

    Exfiltrates data using web services like cloud services (e.g., Google Drive, Dropbox, etc.).

TA0011

Command and Control

  • T1105Ingress Tool Transfer

    Uses certutil to download malicious files.

TA0040

Impact

  • T1486Data Encrypted for Impact

    Uses the AES-256 algorithm to encrypt files on the computer.

  • T1489Service Stop

    Terminates processes and services related to database servers, email servers, and backups.

  • T1490Inhibit System Recovery

    Deletes shadow copies and disables the Windows System Restore feature.

Recent victims

showing 50 of 517
DateWebsite / victimSectorCountry
2026-01-29
balloons.com
Balloons Everywhereballoons.com
Consumer ServicesUS
2026-01-29
southhaysfire.com
South Hays Fire Departmentsouthhaysfire.com
Public SectorUS
2026-02-02
battipaglia.sa.it
Comune di Battipagliabattipaglia.sa.it
Public SectorIT
2026-02-08
grandviewfamilymedicine.com
Grandview Family Medicinegrandviewfamilymedicine.com
HealthcareUS
2026-02-13
mesaproducts.com
MESA Productsmesaproducts.com
ManufacturingUS
2026-01-04
resourcecorp.com
Resource Corporation of Americaresourcecorp.com
HealthcareUS
2025-12-23
J
JBS
HealthcareUS
2025-12-13
thunderbaycounselling.ca
Thunder Bay Counsellingthunderbaycounselling.ca
Public SectorCA
2025-12-13
S
Sampoerna Agro
Agriculture and Food ProductionID
2025-12-13
shamrocktechnologies.com
Shamrock Technologiesshamrocktechnologies.com
TechnologyUS
2025-12-17
callipogroup.it
Callipo Groupcallipogroup.it
Agriculture and Food ProductionIT
2025-11-24
uscs.edu.br
Universidade Municipal de São Caetanouscs.edu.br
EducationBR
2025-11-24Business ServicesBR
2025-11-28
concordacademy.org
Concord Academyconcordacademy.org
EducationUS
2025-11-17Transportation/LogisticsUS
2025-11-17
fdc-interiors.com
FDC Interiorsfdc-interiors.com
ConstructionAE
2025-11-17
mfeformwork.com
MFE Formwork Technologymfeformwork.com
ConstructionSG
2025-11-17
nationwidelegal.com
Nationwide Legal LLCnationwidelegal.com
Business ServicesUS
2025-11-08
atriumlivingcenters.com
Atrium Living Centersatriumlivingcenters.com
HealthcareUS
2025-10-28
simon.com
Simon Property Groupsimon.com
Financial ServicesUS
2025-10-29
C
Clackamas Community College
EducationUS
2025-11-05
L
LaRosa’s Pizzeria
Hospitality and TourismUS
2025-11-05Hospitality and TourismAU
2025-11-06
pamapersada.com
PT Kalimantan Prima Persadapamapersada.com
EnergyID
2025-10-22
adorechildren.org
Adore Children and Family Servicesadorechildren.org
HealthcareUS
2025-10-22HealthcareFR
2025-10-22
cef.it
Cooperativa Esercenti Farmacia Scrlcef.it
HealthcareIT
2025-10-22
alissa-group.com
Alissa Groupalissa-group.com
Agriculture and Food ProductionSA
2025-10-19TechnologyIT
2025-10-19
linxxglobal.com
Linxx Global Solutionslinxxglobal.com
Business ServicesUS
2025-10-19Consumer ServicesFR
2025-10-09
L
Leprohon (Image !)
Construction
2025-10-12
lavoiexpress.ma
LA VOIE EXPRESSlavoiexpress.ma
Transportation/LogisticsMA
2025-10-12
printdaddy.com
Design To Printprintdaddy.com
Business ServicesUS
2025-10-12
ecopetroleo.do
EcoPetróleoecopetroleo.do
EnergyBR
2025-10-13ManufacturingUS
2025-10-07
luxactuaries.com
Lux Actuaries & Consultantsluxactuaries.com
Financial ServicesAE
2025-09-23Business ServicesUS
2025-09-26TelecommunicationUS
2025-09-26HealthcareUS
2025-09-26
insightinhealth.com
Insightin Healthinsightinhealth.com
HealthcareUS
2025-09-27
futuregenerali.in
Future Generalifuturegenerali.in
Financial ServicesIN
2025-10-03ConstructionCA
2025-10-03
L
LGB
ManufacturingGB
2025-09-08EducationTT
2025-09-06
radsolutionsllc.com
Rad-Solutions, LLCradsolutionsllc.com
ManufacturingUS
2025-09-01Financial ServicesUS
2025-09-01ConstructionTH
2025-08-26Financial ServicesGE
2025-08-17
expert.de
Expert E-commerce GmbHexpert.de
TechnologyDE