Medusa Group is a Ransomware-as-a-Service (RaaS) operation targeting corporate networks with double extortion tactics.
Analyst brief
Medusa Group has been active since at least 2021, evolving into a Ransomware-as-a-Service (RaaS) operation, though some attacks may still be conducted directly by core developers. The group primarily targets corporate environments and employs double extortion tactics by exfiltrating data before encryption. Their operations heavily rely on living-off-the-land techniques, including Exploit Public-Facing Application (T1190) for initial access, Windows Management Instrumentation (T1047) for execution, NTDS (T1003.003) for credential access, Remote Desktop Protocol (T1021.001) for lateral movement, and Rclone (T1567.002) for data exfiltration. Defenders should focus on monitoring public-facing application vulnerabilities for initial access attempts, detecting anomalous usage of tools like Mimikatz (S0002) and PsExec (S0029), and blocking or closely monitoring suspicious data transfers to cloud storage services.
Medusa Group
unknown
Medusa Group has been active since at least 2021 and was initially operated as a closed ransomware group before evolving into a Ransomware-as-a-Service (RaaS) operation. Some reporting indicates that certain attacks may still be conducted directly by the ransomware’s core developers. Public sources have also referred to the group as “Spearwing” or “Medusa Actors.” Medusa Group employs living-off-the-land techniques, frequently leveraging publicly available tools and common remote management software to conduct operations. The group engages in double extortion tactics, exfiltrating data prior to encryption and threatening to publish stolen information if ransom demands are not met. For initial access, Medusa Group has exploited publicly known vulnerabilities, conducted phishing campaigns, and used credentials or access purchased from Initial Access Brokers (IABs). The group is opportunistic and has targeted a wide range of sectors globally.
Monitor system logs and process activities to detect suspicious activities related to Service Stop and Inhibit System Recovery.
FAQ2
What is the double extortion tactic used by Medusa Group?+
Medusa Group exfiltrates sensitive data from the victim's network before encrypting it, then threatens to publicly release this data if the ransom is not paid.
What technique does Medusa Group use for initial access?+
Medusa Group uses Exploit Public-Facing Application (T1190) for initial access.