Targets
SN, GB, IR, US, ID
Overview
Medusa is a ransomware-as-a-service operation active since June 2021 that has targeted over 300 victims across critical infrastructure sectors including healthcare, education, legal, and manufacturing using double-extortion, with attacks surging 42% between 2023 and 2024 and a formal CISA advisory issued in early 2025.
Targeted Sectors
Business ServicesTransportation/LogisticsTechnologyFinancialHealthcareHospitality and TourismManufacturingGovernmentAgriculture and Food ProductionNot FoundEnergyEducation
Tools & Malware (27)
MimikatzEDRSandBlastKillAVThrottleStop driverAdvanced IP ScannerNavicatPDQ InventoryRoboCopySoftPerfect NetScanRCloneBITSAdminProcess ExplorerPsExecCloudflaredFRPLigoloPuTTYRevSocksAnyDeskAteraHCL BigFix