ATT&CKReferencesCISA Medusa Group Medusa Ransomware March 2025

CISA Medusa Group Medusa Ransomware March 2025

Cybersecurity and Infrastructure Security Agency. (2025, March 12). AA25-071A #StopRansomware: Medusa Ransomware. Retrieved October 15, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples44

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupMedusa Group

Medusa Group has leveraged Mimikatz to dump LSASS to harvest credentials.

T1016
System Network Configuration Discovery
GroupMedusa Group

Medusa Group has obtained host network details utilizing the command `cmd.exe /c ipconfig /all`.

T1021.001
Remote Desktop Protocol
GroupMedusa Group

Medusa Group has used RDP to conduct lateral movement and exfiltrate data. Medusa Group has also utilized the Windows executable `mstsc.exe` for RDP activities through the command `mstsc.exe /v:{hostname/ip}`.

T1027.010
Command Obfuscation
GroupMedusa Group

Medusa Group has obfuscated PowerShell scripts with Base64 encoding. Medusa Group has also obfuscated the code of dropped kernel drivers using a software known as Safengine Shielden which randomized the code through code mutations and then leveraged an embedded virtual machine interpreter to execute the code.

T1046
Network Service Discovery
GroupMedusa Group

Medusa Group has the capability to use living off the land (LOTL) binaries to perform network enumeration. Medusa Group has also utilized the publicly available scanning tool SoftPerfect Network Scanner (`netscan.exe`) to discover device hostnames and network services.

T1047
Windows Management Instrumentation
GroupMedusa Group

Medusa Group has utilized Windows Management Instrumentation to query system information.

T1059.001
PowerShell
GroupMedusa Group

Medusa Group has leveraged PowerShell for execution and defense evasion. Medusa Group has also utilized PowerShell to execute a bitsadmin transfer from file hosting site.

T1059.003
Windows Command Shell
GroupMedusa Group

Medusa Group has used Windows Command Prompt to control and execute commands on the system to include ingress, network, and filesystem enumeration activities.

T1069.002
Domain Groups
GroupMedusa Group

Medusa Group has utilized the `net group` command to query domain groups within the victim environment.

T1070.003
Clear Command History
GroupMedusa Group

Medusa Group has cleared command history by running the PowerShell command `Remove-Item (Get-PSReadlineOption).HistorySavePath`.

T1070.004
File Deletion
GroupMedusa Group

Medusa Group has deleted previously installed tools.

T1071.001
Web Protocols
GroupMedusa Group

Medusa Group has communicated through reverse or bind shells over port 443 (HTTPS).

T1072
Software Deployment Tools
GroupMedusa Group

Medusa Group has utilized software deployment and management solutions to deploy their encryption payload to include BigFix and PDQ Deploy.

T1078
Valid Accounts
GroupMedusa Group

Medusa Group has utilized compromised legitimate local and domain accounts within the victim environment to facilitate remote access and lateral movement sometimes in combination with PsExec.

T1082
System Information Discovery
GroupMedusa Group

Medusa Group has leveraged `cmd.exe` to identify system info `cmd.exe /c systeminfo`.

T1083
File and Directory Discovery
MalwareMedusa Ransomware

Medusa Ransomware has searched for files within the victim environment for encryption and exfiltration. Medusa Ransomware has also identified files associated with remote management services.

T1083
File and Directory Discovery
GroupMedusa Group

Medusa Group has searched for files within the victim environment for encryption and exfiltration. Medusa Group has also identified files associated with remote management services.

T1105
Ingress Tool Transfer
GroupMedusa Group

Medusa Group has leveraged certutil, PowerShell, and Windows Command to download additional tools to include RMM services. Medusa Group has also engaged in “Bring Your Own Vulnerable Driver” (BYOVD) and downloaded vulnerable or signed drivers to the victim environment to disable security tools.

T1112
Modify Registry
GroupMedusa Group

Medusa Group has modified Registry keys to elevate privileges, maintain persistence and allow remote access.

T1135
Network Share Discovery
GroupMedusa Group

Medusa Group has identified network shares using `cmd.exe /c net share`.

T1136.002
Domain Account
GroupMedusa Group

Medusa Group has created a domain account within the victim environment.

T1190
Exploit Public-Facing Application
GroupMedusa Group

Medusa Group has leveraged public facing vulnerabilities in their campaigns against victim organizations to gain initial access. Medusa Group has also utilized CVE-2024-1709 in ScreenConnect, and CVE-2023-48788 in Fortinet EMS for initial access to victim environments.

T1218.014
MMC
GroupMedusa Group

Medusa Group has leveraged Microsoft Management Console (MMC) to facilitate lateral movement and to interact locally or remotely with victim devices using the command `mmc.exe compmgmt.msc /computer:{hostname/ip}`.

T1219
Remote Access Tools
GroupMedusa Group

Medusa Group has leveraged Remote Access Software for lateral movement and data exfiltration. Medusa Group has also been known to utilize Remote Access Software such as AnyDesk, Atera, ConnectWise, eHorus, N-Able, PDQ Deploy, PDQ Inventory, SimpleHelp and Splashtop.

T1486
Data Encrypted for Impact
GroupMedusa Group

Medusa Group has encrypted files using AES-256 encryption which then appends the file extension “.medusa” to encrypted files and leaves a ransomware note named “!READ_ME_MEDUSA!!!.txt.”

T1486
Data Encrypted for Impact
MalwareMedusa Ransomware

Medusa Ransomware has encrypted files using AES-256 encryption, which then appends the file extension “.medusa” to encrypted files and leaves a ransomware note named “!READ_ME_MEDUSA!!!.txt.”

T1489
Service Stop
MalwareMedusa Ransomware

Medusa Ransomware has the capability to terminate services related to backups, security, databases, communication, filesharing and websites. Medusa Ransomware has also utilized the `taskkill /F /IM <process> /T` command to stop targeted processes and `net stop <process>` command to stop designated services.

T1489
Service Stop
GroupMedusa Group

Medusa Group has terminated services related to backups, security, databases, communication, filesharing and websites.

T1490
Inhibit System Recovery
GroupMedusa Group

Medusa Group has deleted recovery files such as shadow copies using `vssadmin.exe`.

T1490
Inhibit System Recovery
MalwareMedusa Ransomware

Medusa Ransomware has deleted recovery files such as shadow copies using `vssadmin.exe`.

T1529
System Shutdown/Reboot
GroupMedusa Group

Medusa Group has manually turned off and encrypted virtual machines.

T1543.003
Windows Service
GroupMedusa Group

Medusa Group has used vulnerable or signed drivers to modify security solutions on victim devices.

T1553.002
Code Signing
GroupMedusa Group

Medusa Group has utilized vulnerable or signed drivers to kill or delete services associated with endpoint detection and response (EDR) tools.

T1567.002
Exfiltration to Cloud Storage
GroupMedusa Group

Medusa Group has utilized Rclone to exfiltrate data from victim environments to cloud storage.

T1569.002
Service Execution
GroupMedusa Group

Medusa Group has utilized PsExec to execute scripts and commands within victim environments. Medusa Group has also used the Windows service RoboCopy to search and copy data for exfiltration.

T1573.002
Asymmetric Cryptography
GroupMedusa Group

Medusa Group has used HTTPS for command and control.

T1585.002
Email Accounts
GroupMedusa Group

Medusa Group has created email accounts used in ransomware negotiations.

T1588.002
Tool
GroupMedusa Group

Medusa Group has obtained and leveraged numerous RMM services, along with publicly available tools used for scanning. Medusa Group has utilized tools such as Advanced IP Scanner and SoftPerfect Network scanner for user, system and network discovery. Medusa Group has also acquired tools for command and control and defense evasion which include tunneling tools Ligolo and Cloudflared.

T1650
Acquire Access
GroupMedusa Group

Medusa Group has purchased user credentials and other sensitive data from Initial Access Brokers (IABs).

T1652
Device Driver Discovery
GroupMedusa Group

Medusa Group has queried drivers on the victim device through the command `driverquery`.

T1657
Financial Theft
GroupMedusa Group

Medusa Group has stolen and encrypted victims' data in order to extort victims into paying a ransom.

T1685
Disable or Modify Tools
GroupMedusa Group

Medusa Group has terminated antivirus services utilizing the gaze.exe executable and utilizing `psexec.exe`. Medusa Group has also leveraged I/O control codes (IOCTLs) for terminating and deleting processes of identified security tools.

T1686
Disable or Modify System Firewall
GroupMedusa Group

Medusa Group has utilized PsExec to execute batch scripts that modify firewall settings. Medusa Group has also enabled and modified firewall rules to allow for RDP connections for lateral movement and device interactions.

T1690
Prevent Command History Logging
GroupMedusa Group

Medusa Group has removed PowerShell command history through the use of the PSReadLine module by running the PowerShell command `Remove-Item (Get-PSReadlineOption).HistorySavePath`.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.