Medusa
Medium ConfidenceHigh ThreatMedusaLocker • Medusa Blog
Medusa is a ransomware-as-a-service operation that has been active since at least 2021, targeting organizations across education, healthcare, and government sectors. The group operates a leak site called 'Medusa Blog' where they publish stolen data from non-paying victims. Medusa ransomware employs sophisticated encryption techniques and has demonstrated capabilities in evading security controls. The group's operations have affected hundreds of organizations worldwide.
Medusa is a ransomware-as-a-service operation that has been active since at least 2021, targeting organizations across education, healthcare, and government sectors. The group operates a leak site called 'Medusa Blog' where they publish stolen data from non-paying victims. Medusa ransomware employs sophisticated encryption techniques and has demonstrated capabilities in evading security controls. The group's operations have affected hundreds of organizations worldwide.
Target Sectors
Target Regions
Attributed to Cybercriminal (No State Sponsor) (Unknown). Attribution confidence: Medium.
Future Outlook
Medusa is expected to continue operations targeting Healthcare sectors.
First observed activity of Medusa
Continued active operations