ATT&CKReferencesBroadcom Medusa Ransomware Medusa Group March 2025

Broadcom Medusa Ransomware Medusa Group March 2025

Threat Hunter Team Symantec and Carbon Black. (2025, March 6). Medusa Ransomware Activity Continues to Increase. Retrieved October 15, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples26

TechniqueUsed byProcedure example
T1003.003
NTDS
GroupMedusa Group

Medusa Group has accessed the ntds.dit file to engage in credential dumping.

T1007
System Service Discovery
MalwareMedusa Ransomware

Medusa Ransomware has leveraged an encoded list of services that it designates for termination.

T1018
Remote System Discovery
GroupMedusa Group

Medusa Group has used PDQ Inventory to get an inventory of the endpoints on the network.

T1033
System Owner/User Discovery
GroupMedusa Group

Medusa Group has utilized PsExec to execute `quser` to discover the user session information.

T1046
Network Service Discovery
GroupMedusa Group

Medusa Group has the capability to use living off the land (LOTL) binaries to perform network enumeration. Medusa Group has also utilized the publicly available scanning tool SoftPerfect Network Scanner (`netscan.exe`) to discover device hostnames and network services.

T1057
Process Discovery
MalwareMedusa Ransomware

Medusa Ransomware has utilized an encoded list of the processes that it detects and terminates.

T1070.004
File Deletion
MalwareMedusa Ransomware

Medusa Ransomware has the ability to delete itself after execution. Medusa Ransomware also has the ability to delete itself after execution through the command `cmd /c ping localhost -n 3 > nul & del`.

T1087.001
Local Account
GroupMedusa Group

Medusa Group has leveraged `net user` for account discovery.

T1090.003
Multi-hop Proxy
GroupMedusa Group

Medusa Group has used TOR nodes for communications.

T1105
Ingress Tool Transfer
GroupMedusa Group

Medusa Group has leveraged certutil, PowerShell, and Windows Command to download additional tools to include RMM services. Medusa Group has also engaged in “Bring Your Own Vulnerable Driver” (BYOVD) and downloaded vulnerable or signed drivers to the victim environment to disable security tools.

T1135
Network Share Discovery
MalwareMedusa Ransomware

Medusa Ransomware has identified networked drives.

T1190
Exploit Public-Facing Application
GroupMedusa Group

Medusa Group has leveraged public facing vulnerabilities in their campaigns against victim organizations to gain initial access. Medusa Group has also utilized CVE-2024-1709 in ScreenConnect, and CVE-2023-48788 in Fortinet EMS for initial access to victim environments.

T1219
Remote Access Tools
GroupMedusa Group

Medusa Group has leveraged Remote Access Software for lateral movement and data exfiltration. Medusa Group has also been known to utilize Remote Access Software such as AnyDesk, Atera, ConnectWise, eHorus, N-Able, PDQ Deploy, PDQ Inventory, SimpleHelp and Splashtop.

T1486
Data Encrypted for Impact
MalwareMedusa Ransomware

Medusa Ransomware has encrypted files using AES-256 encryption, which then appends the file extension “.medusa” to encrypted files and leaves a ransomware note named “!READ_ME_MEDUSA!!!.txt.”

T1486
Data Encrypted for Impact
GroupMedusa Group

Medusa Group has encrypted files using AES-256 encryption which then appends the file extension “.medusa” to encrypted files and leaves a ransomware note named “!READ_ME_MEDUSA!!!.txt.”

T1489
Service Stop
MalwareMedusa Ransomware

Medusa Ransomware has the capability to terminate services related to backups, security, databases, communication, filesharing and websites. Medusa Ransomware has also utilized the `taskkill /F /IM <process> /T` command to stop targeted processes and `net stop <process>` command to stop designated services.

T1489
Service Stop
GroupMedusa Group

Medusa Group has terminated services related to backups, security, databases, communication, filesharing and websites.

T1490
Inhibit System Recovery
GroupMedusa Group

Medusa Group has deleted recovery files such as shadow copies using `vssadmin.exe`.

T1490
Inhibit System Recovery
MalwareMedusa Ransomware

Medusa Ransomware has deleted recovery files such as shadow copies using `vssadmin.exe`.

T1567.002
Exfiltration to Cloud Storage
GroupMedusa Group

Medusa Group has utilized Rclone to exfiltrate data from victim environments to cloud storage.

T1569.002
Service Execution
GroupMedusa Group

Medusa Group has utilized PsExec to execute scripts and commands within victim environments. Medusa Group has also used the Windows service RoboCopy to search and copy data for exfiltration.

T1570
Lateral Tool Transfer
GroupMedusa Group

Medusa Group has utilized legitimate software services such as PDQ Deploy to transfer malicious binaries and tools to other victimized hosts within the target environment.

T1588.002
Tool
GroupMedusa Group

Medusa Group has obtained and leveraged numerous RMM services, along with publicly available tools used for scanning. Medusa Group has utilized tools such as Advanced IP Scanner and SoftPerfect Network scanner for user, system and network discovery. Medusa Group has also acquired tools for command and control and defense evasion which include tunneling tools Ligolo and Cloudflared.

T1657
Financial Theft
GroupMedusa Group

Medusa Group has stolen and encrypted victims' data in order to extort victims into paying a ransom.

T1679
Selective Exclusion
MalwareMedusa Ransomware

Medusa Ransomware has avoided specified files, file extensions and folders to ensure successful execution of the payload and continued operations of the impacted device.

T1685
Disable or Modify Tools
GroupMedusa Group

Medusa Group has terminated antivirus services utilizing the gaze.exe executable and utilizing `psexec.exe`. Medusa Group has also leveraged I/O control codes (IOCTLs) for terminating and deleting processes of identified security tools.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.