ATT&CKReferencesIntel471 Medusa Ransomware May 2025

Intel471 Medusa Ransomware May 2025

Intel471. (2025, May 14). Threat hunting case study: Medusa ransomware. Retrieved October 15, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples6

TechniqueUsed byProcedure example
T1047
Windows Management Instrumentation
GroupMedusa Group

Medusa Group has utilized Windows Management Instrumentation to query system information.

T1059.001
PowerShell
GroupMedusa Group

Medusa Group has leveraged PowerShell for execution and defense evasion. Medusa Group has also utilized PowerShell to execute a bitsadmin transfer from file hosting site.

T1548.002
Bypass User Account Control
GroupMedusa Group

Medusa Group has attempted to bypass UAC using Component Object Model (COM) interface.

T1559.001
Component Object Model
GroupMedusa Group

Medusa Group has leveraged Component Object Model (COM) to bypass UAC.

T1650
Acquire Access
GroupMedusa Group

Medusa Group has purchased user credentials and other sensitive data from Initial Access Brokers (IABs).

T1657
Financial Theft
GroupMedusa Group

Medusa Group has stolen and encrypted victims' data in order to extort victims into paying a ransom.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.