Skip to content

Medusa

Ransomware Group3 claimsLast activity:
Also known as:
  • Spearwing · Alias

Overview

Medusa is a financially motivated ransomware group whose malware was first identified in June 2021. A joint FBI, CISA and Multi-State Information Sharing and Analysis Center advisory says Medusa began as a closed operation and later adopted a ransomware-as-a-service model. Affiliates conduct intrusions, but the developers retain centralized control over important functions, including ransom negotiations.

The group is also tracked as Spearwing. This operation is unrelated to MedusaLocker ransomware and to mobile malware that uses the Medusa name. Public evidence does not identify Medusa’s operators or establish a state relationship.

Activity and targeting

The federal advisory said Medusa developers and affiliates had affected more than 300 victims across critical infrastructure sectors as of February 2025. Reported industries included medical, education, legal, insurance, technology and manufacturing organizations. Unit 42 described an international victim set with the largest concentration in the United States and additional activity across Europe, Africa, South America and Asia. The range supports an assessment of broad, opportunistic targeting rather than a narrow sector or geographic mandate.

Medusa claims continued into 2026. The group claimed the ransomware attack on the University of Mississippi Medical Center and demanded $800,000, but UMMC did not confirm the attribution or alleged data theft. Leak-site entries and victim totals remain actor claims unless independently corroborated.

Methods and operational characteristics

Medusa uses double extortion: operators steal data, encrypt systems and threaten to publish information if a victim does not pay. Its Tor-based Medusa Blog displays victim names, ransom demands and countdowns. The federal advisory said the site also advertises stolen data for sale and has offered victims the option to pay $10,000 in cryptocurrency for an additional day before publication.

Observed initial-access routes include phishing, exploitation of vulnerable public-facing services and access purchased from initial-access brokers. The federal advisory documented exploitation of ScreenConnect vulnerability CVE-2024-1709 and Fortinet EMS vulnerability CVE-2023-48788. Those are observed routes, not proof that every Medusa intrusion begins the same way.

After entry, reported activity includes PowerShell and Windows command-line execution, remote-management software, credential theft, network discovery, Remote Desktop Protocol and PsExec for movement or deployment, Rclone for exfiltration, and vulnerable or signed drivers used to impair security tools. Unit 42 documented an intrusion involving an exploited Microsoft Exchange server, a web shell, ConnectWise installation and customized network-scanning functions. The Windows encryptor uses AES-256, appends the .medusa extension and attempts to delete recovery data such as shadow copies.

What type of group is it?

Medusa is best classified as a financially motivated ransomware-as-a-service operation with centralized developer control over negotiations and other core functions. That structure separates the developers who maintain the platform from affiliates who may use different access routes and tools. Public reporting includes Cyrillic-language artifacts, but language clues do not establish the operators’ nationality, location or government direction.

Incident claims

Passaic County ransomware incident

View public claim
Incident date: Source: otherPublished: Discovered:

Claim details

Medusa claimed Passaic County, demanded $800,000 and threatened publication. The county did not confirm attribution, and the report did not independently verify responsibility or alleged data theft.

Lehigh Carbon Community College cyber disruption

View public claim
Incident date: Source: otherPublished:

Claim details

Ransomfeed recorded a Medusa listing naming Lehigh Carbon Community College and lccc.edu on March 17. BlackFog separately reported a $100,000 demand and an allegation of exfiltration. LCCC has not confirmed Medusa responsibility, ransomware deployment, data removal or payment.

Impacted organizations

Impacted locations

Sources