ATT&CKReferencesPalo Alto Unit 42 Medusa Group Medusa Ransomware January 2024

Palo Alto Unit 42 Medusa Group Medusa Ransomware January 2024

Anthony Galiette, Doel Santos. (2024, January 11). Medusa Ransomware Turning Your Files into Stone. Retrieved October 15, 2025.

Open the source

Techniques1

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples35

TechniqueUsed byProcedure example
T1007
System Service Discovery
MalwareMedusa Ransomware

Medusa Ransomware has leveraged an encoded list of services that it designates for termination.

T1027.002
Software Packing
GroupMedusa Group

Medusa Group has packed the code of dropped kernel drivers using the packer ASM Guard.

T1027.010
Command Obfuscation
GroupMedusa Group

Medusa Group has obfuscated PowerShell scripts with Base64 encoding. Medusa Group has also obfuscated the code of dropped kernel drivers using a software known as Safengine Shielden which randomized the code through code mutations and then leveraged an embedded virtual machine interpreter to execute the code.

T1027.013
Encrypted/Encoded File
MalwareMedusa Ransomware

Medusa Ransomware has utilized XOR encrypted strings.

T1047
Windows Management Instrumentation
GroupMedusa Group

Medusa Group has utilized Windows Management Instrumentation to query system information.

T1057
Process Discovery
GroupMedusa Group

Medusa Group has utilized a hard-coded security tool process list that identifies and terminates using an undocumented IOCTL code 0x222094.

T1057
Process Discovery
MalwareMedusa Ransomware

Medusa Ransomware has utilized an encoded list of the processes that it detects and terminates.

T1059.001
PowerShell
GroupMedusa Group

Medusa Group has leveraged PowerShell for execution and defense evasion. Medusa Group has also utilized PowerShell to execute a bitsadmin transfer from file hosting site.

T1059.001
PowerShell
MalwareMedusa Ransomware

Medusa Ransomware has launched PowerShell scripts for execution and defense evasion.

T1059.003
Windows Command Shell
MalwareMedusa Ransomware

Medusa Ransomware has used `cmd.exe` to execute command on an infected host.

T1070.004
File Deletion
MalwareMedusa Ransomware

Medusa Ransomware has the ability to delete itself after execution. Medusa Ransomware also has the ability to delete itself after execution through the command `cmd /c ping localhost -n 3 > nul & del`.

T1083
File and Directory Discovery
MalwareMedusa Ransomware

Medusa Ransomware has searched for files within the victim environment for encryption and exfiltration. Medusa Ransomware has also identified files associated with remote management services.

T1083
File and Directory Discovery
GroupMedusa Group

Medusa Group has searched for files within the victim environment for encryption and exfiltration. Medusa Group has also identified files associated with remote management services.

T1090.003
Multi-hop Proxy
GroupMedusa Group

Medusa Group has used TOR nodes for communications.

T1135
Network Share Discovery
MalwareMedusa Ransomware

Medusa Ransomware has identified networked drives.

T1140
Deobfuscate/Decode Files or Information
MalwareMedusa Ransomware

Medusa Ransomware has decoded XOR encrypted strings prior to execution in memory.

T1190
Exploit Public-Facing Application
GroupMedusa Group

Medusa Group has leveraged public facing vulnerabilities in their campaigns against victim organizations to gain initial access. Medusa Group has also utilized CVE-2024-1709 in ScreenConnect, and CVE-2023-48788 in Fortinet EMS for initial access to victim environments.

T1219
Remote Access Tools
GroupMedusa Group

Medusa Group has leveraged Remote Access Software for lateral movement and data exfiltration. Medusa Group has also been known to utilize Remote Access Software such as AnyDesk, Atera, ConnectWise, eHorus, N-Able, PDQ Deploy, PDQ Inventory, SimpleHelp and Splashtop.

T1486
Data Encrypted for Impact
MalwareMedusa Ransomware

Medusa Ransomware has encrypted files using AES-256 encryption, which then appends the file extension “.medusa” to encrypted files and leaves a ransomware note named “!READ_ME_MEDUSA!!!.txt.”

T1486
Data Encrypted for Impact
GroupMedusa Group

Medusa Group has encrypted files using AES-256 encryption which then appends the file extension “.medusa” to encrypted files and leaves a ransomware note named “!READ_ME_MEDUSA!!!.txt.”

T1490
Inhibit System Recovery
MalwareMedusa Ransomware

Medusa Ransomware has deleted recovery files such as shadow copies using `vssadmin.exe`.

T1490
Inhibit System Recovery
GroupMedusa Group

Medusa Group has deleted recovery files such as shadow copies using `vssadmin.exe`.

T1505.003
Web Shell
GroupMedusa Group

Medusa Group has utilized webshells to an exploited Microsoft Exchange Server.

T1518.001
Security Software Discovery
GroupMedusa Group

Medusa Group has detected security solutions for termination or deletion within the victim device using hard-coded lists of strings containing security product executables.

T1518.001
Security Software Discovery
MalwareMedusa Ransomware

Medusa Ransomware has the capability to detect security solutions for termination or deletion within the victim device using hard-coded lists of strings containing security product executables.

T1569.002
Service Execution
GroupMedusa Group

Medusa Group has utilized PsExec to execute scripts and commands within victim environments. Medusa Group has also used the Windows service RoboCopy to search and copy data for exfiltration.

T1583.006
Web Services
GroupMedusa Group

Medusa Group has utilized a file hosting service named filemail[.]com to host a zip file that contained malicious payloads that facilitated follow-on actions.

T1585.001
Social Media Accounts
GroupMedusa Group

Medusa Group has created social media accounts including Telegram and X to publicize their activities.

T1588.002
Tool
GroupMedusa Group

Medusa Group has obtained and leveraged numerous RMM services, along with publicly available tools used for scanning. Medusa Group has utilized tools such as Advanced IP Scanner and SoftPerfect Network scanner for user, system and network discovery. Medusa Group has also acquired tools for command and control and defense evasion which include tunneling tools Ligolo and Cloudflared.

T1608.002
Upload Tool
GroupMedusa Group

Medusa Group has utilized a file hosting service called filemail[.]com to host a zip file that contained a RMM service such as ConnectWise.

T1650
Acquire Access
GroupMedusa Group

Medusa Group has purchased user credentials and other sensitive data from Initial Access Brokers (IABs).

T1657
Financial Theft
GroupMedusa Group

Medusa Group has stolen and encrypted victims' data in order to extort victims into paying a ransom.

T1679
Selective Exclusion
MalwareMedusa Ransomware

Medusa Ransomware has avoided specified files, file extensions and folders to ensure successful execution of the payload and continued operations of the impacted device.

T1685
Disable or Modify Tools
MalwareMedusa Ransomware

Medusa Ransomware has terminated antivirus services utilizing the gaze.exe executable. Medusa Ransomware has also terminated antivirus services utilizing PowerShell scripts.

T1685
Disable or Modify Tools
GroupMedusa Group

Medusa Group has terminated antivirus services utilizing the gaze.exe executable and utilizing `psexec.exe`. Medusa Group has also leveraged I/O control codes (IOCTLs) for terminating and deleting processes of identified security tools.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.