Medusa is a ransomware-as-a-service operation active since 2021, known for double-extortion attacks on over 300 victims in critical sectors.
Analyst brief
Medusa is a ransomware-as-a-service operation active since June 2021, targeting critical infrastructure sectors such as healthcare, education, legal, and manufacturing with double-extortion tactics and over 300 victims. The group saw a 42% surge in attacks between 2023 and 2024, and a formal CISA advisory was issued in early 2025 for defenders. Its core TTPs involve data exfiltration, encryption, and pressure through publishing stolen data. Defenders should prioritize secure authentication, network segmentation, and offline backups per the CISA guidance.
medusa
activecrime
Medusa is a ransomware-as-a-service operation active since June 2021 that has targeted over 300 victims across critical infrastructure sectors including healthcare, education, legal, and manufacturing using double-extortion, with attacks surging 42% between 2023 and 2024 and a formal CISA advisory issued in early 2025.