Overview
Platforms:
—
Variants:
—
Extensions:
.medusa
ATT&CK software:
Medusa Ransomware (S1244) · Mimikatz · PsExec · Rclone · certutil
Initial access:
Exploit Public-Facing Application
Top countries:
—
Observed sectors:
—
Tracked victims:
536
Attribution
Spearwing
VERIFIED
Vendor tracking name
Symantec tracks the threat group responsible for operating Medusa ransomware as Spearwing.
Affiliates
No affiliate information available.
Activity
Recent Observations
High-tempo Medusa campaigns
April 2026
Ransomware activity
Microsoft documented Storm-1175 rapidly exploiting vulnerable internet-facing systems, stealing data and deploying Medusa ransomware, sometimes within 24 hours of initial access.
Continued Medusa victim claims
April 2026
Leak-site activity
Medusa continued publishing victim claims through April 2026.
300+ victims reported
March 2025
Operational scale
A joint U.S. government advisory reported that Medusa developers and affiliates had impacted more than 300 victims across multiple critical infrastructure sectors.
Activity continues to increase
February 2025
Ransomware activity
Symantec reported that Medusa attacks increased substantially during 2024 and accelerated further during the first two months of 2025.
TTPs
ATT&CK coverage:
7 techniques
· 6 tactics
T1190
Exploit Public-Facing Application
VERIFIEDInitial Access
Medusa actors exploit vulnerabilities in internet-facing applications and perimeter systems for initial access.
T1059.001
PowerShell
VERIFIEDExecution
Medusa actors use PowerShell for execution, tool transfer and defense-evasion activity.
T1003.001
LSASS Memory
VERIFIEDCredential Access
Medusa operations have used Mimikatz to obtain credentials from LSASS memory.
Show more TTPs (4)
T1021.001
Remote Desktop Protocol
VERIFIEDLateral Movement
Medusa actors use Remote Desktop Protocol to move laterally through compromised environments.
T1567.002
Exfiltration to Cloud Storage
VERIFIEDExfiltration
Medusa operations have used Rclone to transfer stolen information from victim environments.
T1490
Inhibit System Recovery
VERIFIEDImpact
Medusa ransomware can interfere with recovery mechanisms before encryption.
T1486
Data Encrypted for Impact
VERIFIEDImpact
Medusa encrypts victim files using AES-256 and appends the .medusa extension.
Victims
University of Mississippi Medical Center
CLAIMED
Healthcare organization in United States.
CVEs
ConnectWise
— ScreenConnect
Medusa actors have exploited this authentication-bypass vulnerability in ScreenConnect for initial access.
Associated since:
February 2024
Fortinet
— FortiClient EMS
Medusa actors have exploited this SQL injection vulnerability in FortiClient EMS for initial access.
Associated since:
March 2024
Fortra
— GoAnywhere MFT
Storm-1175 exploited this vulnerability as a zero-day during campaigns associated with Medusa ransomware deployment.
Associated since:
September 2025
Show more CVEs (1)
SAP
— NetWeaver Visual Composer
Microsoft observed Storm-1175 exploiting this vulnerability shortly after disclosure during its high-tempo ransomware operations.
Associated since:
April 2025
Infrastructure
Medusa leak site
Medusa operates public data leak infrastructure used to publish victim claims and stolen information as part of its double-extortion model.
Extortion communications
Medusa uses dedicated negotiation and public communication channels to pressure victims and manage extortion activity.
Timeline
2026-08
Government advisory updated
CISA, FBI and HHS updated their Medusa advisory with additional investigation findings and indicators observed through 2026.
2026-04
More than 500 victims
FBI investigations documented more than 500 victims impacted by Medusa developers and affiliates as of April 2026.
2026-03
High-tempo Medusa deployment
Microsoft observed Storm-1175 compromising exposed systems and deploying Medusa ransomware in rapidly executed attack chains.
Show more events (4)
2025-09
GoAnywhere zero-day exploitation
Storm-1175 exploited CVE-2025-10035 in GoAnywhere MFT as a zero-day during Medusa-associated intrusion activity.
2025-03
U.S. government advisory
CISA, FBI and HHS published a joint advisory after Medusa developers and affiliates had impacted more than 300 victims.
2023-02
Public leak-site activity
Medusa began publishing victim claims through dedicated public data leak infrastructure.
2021-06
Medusa first identified
Medusa ransomware was first identified as a closed ransomware operation before later evolving toward an affiliate model.
Sources
#StopRansomware: Medusa Ransomware
CISA / FBI / HHS
Show more sources (6)
Storm-1175 focuses gaze on vulnerable web-facing assets in high-tempo Medusa ransomware operations
Microsoft Threat Intelligence
Vendor research
Investigating active exploitation of CVE-2025-10035 GoAnywhere MFT
Microsoft Threat Intelligence
UMMC prioritizes care and recovery during cyberattack
University of Mississippi Medical Center