Widely attributedUnknownMITRE G1051

Medusa Group

Medusa Group has been active since at least 2021 and was initially operated as a closed ransomware group before evolving into a Ransomware-as-a-Service (RaaS) operation. Some reporting indicates that certain attacks may still be conducted directly by the ransomware’s core developers. Public sources have also referred to the group as “Spearwing” or “Medusa Actors.” Medusa Group employs living-off-the-land techniques, frequently leveraging publicly available tools and common remote management software to conduct operations. The group engages in double extortion tactics, exfiltrating data prior to encryption and threatening to publish stolen information if ransom demands are not met. For initial access, Medusa Group has exploited publicly known vulnerabilities, conducted phishing campaigns, and used credentials or access purchased from Initial Access Brokers (IABs). The group is opportunistic and has targeted a wide range of sectors globally.

Attribution signal

?Score = mentions × confidence weight, summed across all attributed sources. Higher source diversity increases the score.≥ 10 High≥ 3 Moderate< 3 Low
0.1
Low signal strength
Mentions1
Sources0
High conf.0
Last seenJun 2026
First observed
2025-10-15
Last active
Origin
Unknown — financially motivated cybercriminal group
Aliases
1
Techniques
57
Campaigns
0

Attribution signals

1 mention · 0 sources
#1unspecifiedunspecified
Unspecified
coveware
Jun 2026

"a member of the Medusa ransomware gang approached an employee of an organization, offering him a 15% cut of a ransom payment in exchange for network access"

Hedge terms observed

unspecified