Anthony Galiette, Doel Santos. (2024, January 11). Medusa Ransomware Turning Your Files into Stone. Retrieved October 15, 2025.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1007 System Service Discovery |
MalwareMedusa Ransomware | Medusa Ransomware has leveraged an encoded list of services that it designates for termination. |
| T1027.002 Software Packing |
GroupMedusa Group | Medusa Group has packed the code of dropped kernel drivers using the packer ASM Guard. |
| T1027.010 Command Obfuscation |
GroupMedusa Group | Medusa Group has obfuscated PowerShell scripts with Base64 encoding. Medusa Group has also obfuscated the code of dropped kernel drivers using a software known as Safengine Shielden which randomized the code through code mutations and then leveraged an embedded virtual machine interpreter to execute the code. |
| T1027.013 Encrypted/Encoded File |
MalwareMedusa Ransomware | Medusa Ransomware has utilized XOR encrypted strings. |
| T1047 Windows Management Instrumentation |
GroupMedusa Group | Medusa Group has utilized Windows Management Instrumentation to query system information. |
| T1057 Process Discovery |
GroupMedusa Group | Medusa Group has utilized a hard-coded security tool process list that identifies and terminates using an undocumented IOCTL code 0x222094. |
| T1057 Process Discovery |
MalwareMedusa Ransomware | Medusa Ransomware has utilized an encoded list of the processes that it detects and terminates. |
| T1059.001 PowerShell |
GroupMedusa Group | Medusa Group has leveraged PowerShell for execution and defense evasion. Medusa Group has also utilized PowerShell to execute a bitsadmin transfer from file hosting site. |
| T1059.001 PowerShell |
MalwareMedusa Ransomware | Medusa Ransomware has launched PowerShell scripts for execution and defense evasion. |
| T1059.003 Windows Command Shell |
MalwareMedusa Ransomware | Medusa Ransomware has used `cmd.exe` to execute command on an infected host. |
| T1070.004 File Deletion |
MalwareMedusa Ransomware | Medusa Ransomware has the ability to delete itself after execution. Medusa Ransomware also has the ability to delete itself after execution through the command `cmd /c ping localhost -n 3 > nul & del`. |
| T1083 File and Directory Discovery |
MalwareMedusa Ransomware | Medusa Ransomware has searched for files within the victim environment for encryption and exfiltration. Medusa Ransomware has also identified files associated with remote management services. |
| T1083 File and Directory Discovery |
GroupMedusa Group | Medusa Group has searched for files within the victim environment for encryption and exfiltration. Medusa Group has also identified files associated with remote management services. |
| T1090.003 Multi-hop Proxy |
GroupMedusa Group | Medusa Group has used TOR nodes for communications. |
| T1135 Network Share Discovery |
MalwareMedusa Ransomware | Medusa Ransomware has identified networked drives. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareMedusa Ransomware | Medusa Ransomware has decoded XOR encrypted strings prior to execution in memory. |
| T1190 Exploit Public-Facing Application |
GroupMedusa Group | Medusa Group has leveraged public facing vulnerabilities in their campaigns against victim organizations to gain initial access. Medusa Group has also utilized CVE-2024-1709 in ScreenConnect, and CVE-2023-48788 in Fortinet EMS for initial access to victim environments. |
| T1219 Remote Access Tools |
GroupMedusa Group | Medusa Group has leveraged Remote Access Software for lateral movement and data exfiltration. Medusa Group has also been known to utilize Remote Access Software such as AnyDesk, Atera, ConnectWise, eHorus, N-Able, PDQ Deploy, PDQ Inventory, SimpleHelp and Splashtop. |
| T1486 Data Encrypted for Impact |
MalwareMedusa Ransomware | Medusa Ransomware has encrypted files using AES-256 encryption, which then appends the file extension “.medusa” to encrypted files and leaves a ransomware note named “!READ_ME_MEDUSA!!!.txt.” |
| T1486 Data Encrypted for Impact |
GroupMedusa Group | Medusa Group has encrypted files using AES-256 encryption which then appends the file extension “.medusa” to encrypted files and leaves a ransomware note named “!READ_ME_MEDUSA!!!.txt.” |
| T1490 Inhibit System Recovery |
MalwareMedusa Ransomware | Medusa Ransomware has deleted recovery files such as shadow copies using `vssadmin.exe`. |
| T1490 Inhibit System Recovery |
GroupMedusa Group | Medusa Group has deleted recovery files such as shadow copies using `vssadmin.exe`. |
| T1505.003 Web Shell |
GroupMedusa Group | Medusa Group has utilized webshells to an exploited Microsoft Exchange Server. |
| T1518.001 Security Software Discovery |
GroupMedusa Group | Medusa Group has detected security solutions for termination or deletion within the victim device using hard-coded lists of strings containing security product executables. |
| T1518.001 Security Software Discovery |
MalwareMedusa Ransomware | Medusa Ransomware has the capability to detect security solutions for termination or deletion within the victim device using hard-coded lists of strings containing security product executables. |
| T1569.002 Service Execution |
GroupMedusa Group | Medusa Group has utilized PsExec to execute scripts and commands within victim environments. Medusa Group has also used the Windows service RoboCopy to search and copy data for exfiltration. |
| T1583.006 Web Services |
GroupMedusa Group | Medusa Group has utilized a file hosting service named filemail[.]com to host a zip file that contained malicious payloads that facilitated follow-on actions. |
| T1585.001 Social Media Accounts |
GroupMedusa Group | Medusa Group has created social media accounts including Telegram and X to publicize their activities. |
| T1588.002 Tool |
GroupMedusa Group | Medusa Group has obtained and leveraged numerous RMM services, along with publicly available tools used for scanning. Medusa Group has utilized tools such as Advanced IP Scanner and SoftPerfect Network scanner for user, system and network discovery. Medusa Group has also acquired tools for command and control and defense evasion which include tunneling tools Ligolo and Cloudflared. |
| T1608.002 Upload Tool |
GroupMedusa Group | Medusa Group has utilized a file hosting service called filemail[.]com to host a zip file that contained a RMM service such as ConnectWise. |
| T1650 Acquire Access |
GroupMedusa Group | Medusa Group has purchased user credentials and other sensitive data from Initial Access Brokers (IABs). |
| T1657 Financial Theft |
GroupMedusa Group | Medusa Group has stolen and encrypted victims' data in order to extort victims into paying a ransom. |
| T1679 Selective Exclusion |
MalwareMedusa Ransomware | Medusa Ransomware has avoided specified files, file extensions and folders to ensure successful execution of the payload and continued operations of the impacted device. |
| T1685 Disable or Modify Tools |
MalwareMedusa Ransomware | Medusa Ransomware has terminated antivirus services utilizing the gaze.exe executable. Medusa Ransomware has also terminated antivirus services utilizing PowerShell scripts. |
| T1685 Disable or Modify Tools |
GroupMedusa Group | Medusa Group has terminated antivirus services utilizing the gaze.exe executable and utilizing `psexec.exe`. Medusa Group has also leveraged I/O control codes (IOCTLs) for terminating and deleting processes of identified security tools. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.