Medusa is an advanced Ransomware-as-a-Service (RaaS) operation that emerged in 2021. Its affiliates use this service to conduct double extortion attacks targeting multiple sectors globally. Medusa's architecture includes centralized negotiation portals, consistent use of living-off-the-land (LOTL) techniques, and persistent exploitation of high-profile vulnerabilities.
Medusa affiliates commonly leverage:
Tools and techniques observed:
CISA provides detailed IOCs in STIX formats:
Common artifacts include: