White Paper
THREAT PROFILE: Medusa Ransomware
Medusa is a ransomware-as-a-service (RaaS) group first identified in 2022 that employs a double-extortion strategy, combining file encryption with the theft of sensitive data to pressure victims into paying a ransom. If demands are not met, the group threatens to publish stolen information through a dedicated data leak site. Medusa has frequently targeted organizations in industrial sectors, particularly construction and engineering, where operational disruptions can have significant business impacts. This threat profile examines the group’s targeted industries and regions, known exploited vulnerabilities, associated threat actors, and tools used during attacks. It also analyzes observed behaviors in Windows environments and maps Medusa’s tactics, techniques, and procedures to the MITRE AT
