Overview

Platforms: —
Variants: —
Extensions: .medusa
ATT&CK software: Medusa Ransomware (S1244) · Mimikatz · PsExec · Rclone · certutil
Initial access: Exploit Public-Facing Application
Top countries: —
Observed sectors: —
Tracked victims: 536

Attribution

Spearwing VERIFIED
Vendor tracking name
Symantec tracks the threat group responsible for operating Medusa ransomware as Spearwing.

Affiliates

No affiliate information available.

Activity

Recent Observations

High-tempo Medusa campaigns
April 2026
Ransomware activity
Microsoft documented Storm-1175 rapidly exploiting vulnerable internet-facing systems, stealing data and deploying Medusa ransomware, sometimes within 24 hours of initial access.
Continued Medusa victim claims
April 2026
Leak-site activity
Medusa continued publishing victim claims through April 2026.
300+ victims reported
March 2025
Operational scale
A joint U.S. government advisory reported that Medusa developers and affiliates had impacted more than 300 victims across multiple critical infrastructure sectors.
Activity continues to increase
February 2025
Ransomware activity
Symantec reported that Medusa attacks increased substantially during 2024 and accelerated further during the first two months of 2025.

TTPs

ATT&CK coverage: 7 techniques · 6 tactics
T1190 Exploit Public-Facing Application
VERIFIED
Initial Access
Medusa actors exploit vulnerabilities in internet-facing applications and perimeter systems for initial access.
T1059.001 PowerShell
VERIFIED
Execution
Medusa actors use PowerShell for execution, tool transfer and defense-evasion activity.
T1003.001 LSASS Memory
VERIFIED
Credential Access
Medusa operations have used Mimikatz to obtain credentials from LSASS memory.
Show more TTPs (4)
T1021.001 Remote Desktop Protocol
VERIFIED
Lateral Movement
Medusa actors use Remote Desktop Protocol to move laterally through compromised environments.
T1567.002 Exfiltration to Cloud Storage
VERIFIED
Exfiltration
Medusa operations have used Rclone to transfer stolen information from victim environments.
T1490 Inhibit System Recovery
VERIFIED
Impact
Medusa ransomware can interfere with recovery mechanisms before encryption.
T1486 Data Encrypted for Impact
VERIFIED
Impact
Medusa encrypts victim files using AES-256 and appends the .medusa extension.

Victims

University of Mississippi Medical Center CLAIMED
February 2026 United States Healthcare 2 tracker sources
Healthcare organization in United States.

CVEs

ConnectWise — ScreenConnect
Medusa actors have exploited this authentication-bypass vulnerability in ScreenConnect for initial access.
Associated since: February 2024
Fortinet — FortiClient EMS
Medusa actors have exploited this SQL injection vulnerability in FortiClient EMS for initial access.
Associated since: March 2024
Fortra — GoAnywhere MFT
Storm-1175 exploited this vulnerability as a zero-day during campaigns associated with Medusa ransomware deployment.
Associated since: September 2025
Show more CVEs (1)
SAP — NetWeaver Visual Composer
Microsoft observed Storm-1175 exploiting this vulnerability shortly after disclosure during its high-tempo ransomware operations.
Associated since: April 2025

Infrastructure

Medusa leak site
Medusa operates public data leak infrastructure used to publish victim claims and stolen information as part of its double-extortion model.
Extortion communications
Medusa uses dedicated negotiation and public communication channels to pressure victims and manage extortion activity.

Timeline

2026-08
Government advisory updated
CISA, FBI and HHS updated their Medusa advisory with additional investigation findings and indicators observed through 2026.
2026-04
More than 500 victims
FBI investigations documented more than 500 victims impacted by Medusa developers and affiliates as of April 2026.
2026-03
High-tempo Medusa deployment
Microsoft observed Storm-1175 compromising exposed systems and deploying Medusa ransomware in rapidly executed attack chains.
Show more events (4)
2025-09
GoAnywhere zero-day exploitation
Storm-1175 exploited CVE-2025-10035 in GoAnywhere MFT as a zero-day during Medusa-associated intrusion activity.
2025-03
U.S. government advisory
CISA, FBI and HHS published a joint advisory after Medusa developers and affiliates had impacted more than 300 victims.
2023-02
Public leak-site activity
Medusa began publishing victim claims through dedicated public data leak infrastructure.
2021-06
Medusa first identified
Medusa ransomware was first identified as a closed ransomware operation before later evolving toward an affiliate model.

Sources