CYBERSECURITYTRACKER
TRACKING7,811 stories in this site build1,697 vulnerability news stories in this site build
Incidents

Medusa

Review this actor's tracked leak-site claims, published reporting, and attributed threat evidence.

ransomware537 leak-site claims, all timeLatest observed leak-site post 2026-04-26MITRE ATT&CK G1051 ↗ORKL search ↗

Portable threat brief

Medusa

Facts from stored data only; no AI-written text.

Opens the browser print dialog; choose Save as PDF.

PDF export is unavailable. The threat brief remains available below; use your browser's Print command.

Executive facts

Actor
Medusa
Kind
ransomware
Actor record created
2026-04-26
Latest observed
2026-04-26
Leak-site claims
537
ATT&CK group
G1051
Catalogued techniques
57
How linked to MITRE:
MITRE's name or alias matches this group

Scope

Tracked sectors
Healthcare, Manufacturing, Construction & Engineering, Government, Education
Claim records
2023-02-13 to 2026-04-26
News stories naming this group
2025-03-12 to 2026-09-18

Vulnerability events linked to this group

No dated vulnerability events are attached to this group's linked vulnerabilities.

Verified techniques

Derived only from this actor's stored verified ATT&CK group-to-technique mappings (ATT&CK 19.2); phases are not scored. MITRE group provenance.

Defensive actions

  • M1026Privileged Account Management12 techniques
  • M1018User Account Management11 techniques
  • M1038Execution Prevention9 techniques
  • M1028Operating System Configuration8 techniques
  • M1040Behavior Prevention on Endpoint7 techniques
  • M1042Disable or Remove Feature or Program7 techniques
  • M1030Network Segmentation6 techniques
  • M1031Network Intrusion Prevention6 techniques
  • M1037Filter Network Traffic6 techniques
  • M1056Pre-compromise6 techniques

Ransomware claim data is unverified: RansomLook (CC BY 4.0).

MITRE ATT&CK names and links © The MITRE Corporation.

Most-claimed sectorsHealthcareManufacturingConstruction & EngineeringGovernmentEducation
Activity window in this site's data

This is only the dates observed by this site. It is not this actor's lifetime or evidence of dormancy outside these dates.

Claim records
First observed Latest observed
News stories naming this group
First observed Latest observed
Verified ATT&CK phases represented

Derived only from this actor's stored verified ATT&CK group-to-technique mappings (ATT&CK 19.2); phases are not scored.

Origin and motivation

Origin and motivation not attributed.

Claims posted under this group's name or leak-site brand
537 on this site
View all on Breaches →
Leak-site claim activity

0 additional claims without a disclosure date

2023-022026-04
Defensive actions

The MITRE ATT&CK mitigations countering the most of this group's known techniques, derived automatically from MITRE's own group and mitigation data. Each links to the full guidance with NIST 800-53 controls and authoritative configuration sources.

All defensive actions for Medusa →
Detection rules

SigmaHQ detection rules mapped to this group's MITRE ATT&CK techniques. One technique maps to many rules, so this shows the top few by status and severity, with a link to the full set on SigmaHQ.

Detection rules for MedusaShowing 8 of 451
Author: Florian Roth (Nextron Systems), Arnim Rupp

Detection prerequisites: Log source: antivirus

False positives: Unlikely

title: Antivirus - Exploitation Framework Signature
id: 238527ad-3c2c-4e4f-a1f6-92fd63adb864
status: stable
description: |
    Detects a highly relevant Antivirus alert that reports an exploitation framework.
    This event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place.
references:
    - https://www.nextron-systems.com/?s=antivirus
    - https://www.virustotal.com/gui/file/925b0b28472d4d79b4bf92050e38cc2b8f722691c713fc28743ac38551bc3797
    - https://www.virustotal.com/gui/file/8f8daabe1c8ceb5710949283818e16c4aa8059bf2ce345e2f2c90b8692978424
    - https://www.virustotal.com/gui/file/d9669f7e3eb3a9cdf6a750eeb2ba303b5ae148a43e36546896f1d1801e912466
author: Florian Roth (Nextron Systems), Arnim Rupp
date: 2018-09-09
modified: 2026-06-15
tags:
    - attack.execution
    - attack.t1203
    - attack.command-and-control
    - attack.t1219.002
logsource:
    category: antivirus
detection:
    selection:
        Signature|contains:
            - 'ATK/Cobalt'
            - 'Backdoor.Cobalt'
            - 'Beacon'
            - 'Brutel'
            - 'BruteR'
            - 'CbltStr'
            - 'CobaltStr'
            - 'COBALT.SMD'
            - 'COBEACON'
            - 'Cometer'
            - 'Exploit.Script.CVE'
            - 'IISExchgSpawnCMD'
            - 'Metasploit'
            - 'Meterpreter'
            - 'MeteTool'
            - 'Mpreter'
            - 'MsfShell'
            - 'PowerSploit'
            - 'Razy'
            - 'Rozena'
            - 'Sbelt'
            - 'Seatbelt'
            - 'Sliver'
            - 'Swrort'
    condition: selection
falsepositives:
    - Unlikely
level: critical
View this rule on SigmaHQ ↗
Author: Florian Roth (Nextron Systems), Arnim Rupp

Detection prerequisites: Log source: antivirus

False positives: Unlikely

title: Antivirus - Password Dumper Signature
id: 78cc2dd2-7d20-4d32-93ff-057084c38b93
status: stable
description: |
    Detects a highly relevant Antivirus alert that reports password dumpers and stealers.
    This event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place and check if passwords need to be reset.
references:
    - https://www.nextron-systems.com/?s=antivirus
    - https://www.virustotal.com/gui/file/5fcda49ee7f202559a6cbbb34edb65c33c9a1e0bde9fa2af06a6f11b55ded619
    - https://www.virustotal.com/gui/file/a4edfbd42595d5bddb442c82a02cf0aaa10893c1bf79ea08b9ce576f82749448
author: Florian Roth (Nextron Systems), Arnim Rupp
date: 2018-09-09
modified: 2026-06-15
tags:
    - attack.credential-access
    - attack.t1003
    - attack.t1558
    - attack.t1003.001
    - attack.t1003.002
logsource:
    category: antivirus
detection:
    selection:
        - Signature|startswith: 'PWS'
        - Signature|contains:
              - 'Certify'
              - 'DCSync'
              - 'Creddump'
              - 'DumpCreds'
              - 'DumpLsass'
              - 'DumpPert'
              - 'FormBook'
              - 'HTool/WCE'
              - 'Kekeo'
              - 'Lazagne'
              - 'LsassDump'
              - 'Lummast'
              - 'Mimikatz'
              - 'MultiDump'
              - 'Multiverze'
              - 'Nanodump'
              - 'NativeDump'
              - 'Outflank'
              - 'PShlSpy'
              - 'PSWTool'
              - 'PWCrack'
              - 'PWDump'
              - 'PWS.'
              - 'PWSX'
              - 'pypykatz'
              - 'Rubeus'
              - 'SafetyKatz'
              - 'SecurityTool'
              - 'SharpChrome'
              - 'SharpDPAPI'
              - 'SharpDump'
              - 'SharpKatz'
              - 'SharpS.' # Sharpsploit, e.g. 530ea2ff9049f5dfdfa0a2e9c27c2e3c0685eb6cbdf85370c20a7bfae49f592d
              - 'ShpKatz'
              - 'Steal'
              - 'TrickDump'
              - 'wsass'
    condition: selection
falsepositives:
    - Unlikely
level: critical
View this rule on SigmaHQ ↗
Author: Ecco

Detection prerequisites: Platform: windows · Log source: process_creation

False positives: Unknown

title: HackTool - Empire PowerShell UAC Bypass
id: 3268b746-88d8-4cd3-bffc-30077d02c787
status: stable
description: Detects some Empire PowerShell UAC bypass methods
references:
    - https://github.com/EmpireProject/Empire/blob/e37fb2eef8ff8f5a0a689f1589f424906fe13055/data/module_source/privesc/Invoke-EventVwrBypass.ps1#L64
    - https://github.com/EmpireProject/Empire/blob/e37fb2eef8ff8f5a0a689f1589f424906fe13055/data/module_source/privesc/Invoke-FodHelperBypass.ps1#L64
author: Ecco
date: 2019-08-30
modified: 2023-02-21
tags:
    - attack.privilege-escalation
    - attack.t1548.002
    - car.2019-04-001
logsource:
    category: process_creation
    product: windows
detection:
    selection:
        CommandLine|contains:
            - ' -NoP -NonI -w Hidden -c $x=$((gp HKCU:Software\Microsoft\Windows Update).Update)'
            - ' -NoP -NonI -c $x=$((gp HKCU:Software\Microsoft\Windows Update).Update);'
    condition: selection
falsepositives:
    - Unknown
level: critical
View this rule on SigmaHQ ↗
Author: Vasiliy Burov, oscd.community

Detection prerequisites: Platform: windows · Log source: process_creation

False positives: Unlikely

title: LockerGoga Ransomware Activity
id: 74db3488-fd28-480a-95aa-b7af626de068
status: stable
description: Detects LockerGoga ransomware activity via specific command line.
references:
    - https://medium.com/@malwaredancer/lockergoga-input-arguments-ipc-communication-and-others-bd4e5a7ba80a
    - https://blog.f-secure.com/analysis-of-lockergoga-ransomware/
    - https://www.carbonblack.com/blog/tau-threat-intelligence-notification-lockergoga-ransomware/
author: Vasiliy Burov, oscd.community
date: 2020-10-18
modified: 2023-02-03
tags:
    - attack.impact
    - attack.t1486
    - detection.emerging-threats
logsource:
    category: process_creation
    product: windows
detection:
    selection:
        CommandLine|contains: '-i SM-tgytutrc -s'
    condition: selection
falsepositives:
    - Unlikely
level: critical
View this rule on SigmaHQ ↗
Author: Florian Roth (Nextron Systems), oscd.community, Nasreddine Bencherchali (Nextron Systems)

Detection prerequisites: Platform: windows · Log source: process_creation

False positives: Unlikely

title: Potential Dridex Activity
id: e6eb5a96-9e6f-4a18-9cdd-642cfda21c8e
status: stable
description: Detects potential Dridex acitvity via specific process patterns
references:
    - https://app.any.run/tasks/993daa5e-112a-4ff6-8b5a-edbcec7c7ba3
    - https://redcanary.com/threat-detection-report/threats/dridex/
author: Florian Roth (Nextron Systems), oscd.community, Nasreddine Bencherchali (Nextron Systems)
date: 2019-01-10
modified: 2023-02-03
tags:
    - attack.privilege-escalation
    - attack.stealth
    - attack.t1055
    - attack.discovery
    - attack.t1135
    - attack.t1033
    - detection.emerging-threats
logsource:
    category: process_creation
    product: windows
detection:
    selection_svchost:
        Image|endswith: '\svchost.exe'
        CommandLine|contains|all:
            - 'C:\Users\'
            - '\Desktop\'
    filter_svchost:
        ParentImage|startswith: 'C:\Windows\System32\'
    selection_regsvr:
        ParentImage|endswith: '\excel.exe'
        Image|endswith: '\regsvr32.exe'
        CommandLine|contains:
            - ' -s '
            - '\AppData\Local\Temp\'
    filter_regsvr:
        CommandLine|contains: '.dll'
    selection_anomaly_parent:
        ParentImage|endswith: '\svchost.exe'
    selection_anomaly_child_1:
        Image|endswith: '\whoami.exe'
        CommandLine|contains: ' /all'
    selection_anomaly_child_2:
        Image|endswith:
            - '\net.exe'
            - '\net1.exe'
        CommandLine|contains: ' view'
    condition: (selection_svchost and not filter_svchost) or (selection_regsvr and not filter_regsvr) or (selection_anomaly_parent and 1 of selection_anomaly_child_*)
falsepositives:
    - Unlikely
level: critical
View this rule on SigmaHQ ↗
Author: Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)

Detection prerequisites: Platform: windows · Log source: process_creation

False positives: Unlikely

title: Potential Dtrack RAT Activity
id: f1531fa4-5b84-4342-8f68-9cf3fdbd83d4
status: stable
description: Detects potential Dtrack RAT activity via specific process patterns
references:
    - https://securelist.com/my-name-is-dtrack/93338/
    - https://securelist.com/andariel-deploys-dtrack-and-maui-ransomware/107063/
    - https://www.cyberbit.com/endpoint-security/dtrack-apt-malware-found-in-nuclear-power-plant/
    - https://app.any.run/tasks/4bc9860d-ab51-4077-9e09-59ad346b92fd/
    - https://app.any.run/tasks/ce4deab5-3263-494f-93e3-afb2b9d79f14/
author: Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
date: 2019-10-30
modified: 2025-11-03
tags:
    - attack.impact
    - attack.t1490
    - detection.emerging-threats
logsource:
    category: process_creation
    product: windows
detection:
    selection_ping:
        CommandLine|re: 'ping\s+-n.{6,64}echo EEEE\s?>\s?'
    selection_ipconfig:
        CommandLine|re: 'ipconfig\s+/all'
        CommandLine|contains: '\temp\res.ip'
    selection_netsh:
        CommandLine|contains|all:
            - 'interface ip show config'
            - '\temp\netsh.res'
    condition: 1 of selection_*
falsepositives:
    - Unlikely
level: critical
View this rule on SigmaHQ ↗
Author: Florian Roth (Nextron Systems)

Detection prerequisites: Platform: windows · Log source: process_creation

False positives: Unlikely

title: Potential Russian APT Credential Theft Activity
id: b83f5166-9237-4b5e-9cd4-7b5d52f4d8ee
status: stable
description: Detects Russian group activity as described in Global Threat Report 2019 by Crowdstrike
references:
    - https://www.documentcloud.org/documents/5743766-Global-Threat-Report-2019.html
author: Florian Roth (Nextron Systems)
date: 2019-02-21
modified: 2023-03-08
tags:
    - attack.credential-access
    - attack.t1552.001
    - attack.t1003.003
    - detection.emerging-threats
logsource:
    category: process_creation
    product: windows
detection:
    selection_xcopy:
        CommandLine|contains|all:
            - 'xcopy /S /E /C /Q /H \\\\'
            - '\sysvol\'
    selection_adexplorer:
        CommandLine|contains|all:
            - 'adexplorer -snapshot "" c:\users\'
            - '\downloads\'
            - '.snp'
    condition: 1 of selection_*
falsepositives:
    - Unlikely
level: critical
View this rule on SigmaHQ ↗
Author: Thomas Patzke

Detection prerequisites: Log source: proxy

False positives: Unknown

title: Ursnif Malware C2 URL Pattern
id: 932ac737-33ca-4afd-9869-0d48b391fcc9
status: stable
description: Detects Ursnif C2 traffic.
references:
    - https://www.fortinet.com/blog/threat-research/ursnif-variant-spreading-word-document.html
author: Thomas Patzke
date: 2019-12-19
modified: 2021-08-09
tags:
    - attack.initial-access
    - attack.t1566.001
    - attack.execution
    - attack.t1204.002
    - attack.command-and-control
    - attack.t1071.001
    - detection.emerging-threats
logsource:
    category: proxy
detection:
    b64encoding:
        c-uri|contains:
            - '_2f'
            - '_2b'
    urlpatterns:
        c-uri|contains|all:
            - '.avi'
            - '/images/'
    condition: b64encoding and urlpatterns
falsepositives:
    - Unknown
level: critical
View this rule on SigmaHQ ↗
View all detecting rules on SigmaHQ →

Detection rules licensed under Detection Rule License (DRL) 1.1, from SigmaHQ. Each rule retains its author.

Validation tests

Atomic Red Team validating tests mapped to this group's MITRE ATT&CK techniques, shown beside the detection rules so you can validate the detections. This shows the top few, with a link to the full set on GitHub. Descriptive metadata only, never the attack commands.

Validating tests for MedusaShowing 8 of 437
Platforms: windows

Red teamer's avoid IEX and Invoke-WebRequest in your PowerShell commands. Instead, host a text record with a payload to compromise hosts. [reference](https://twitter.com/jstrosch/status/1237382986557001729)

View this test on GitHub ↗
Platforms: linux

Use Admin Credentials to Create A Domain Admin Account

View this test on GitHub ↗
Platforms: linux

Use Admin Credentials to Create A Normal Account (as means of entry)

View this test on GitHub ↗
Platforms: linux

Output information from LDAPSearch. LDAP Password is the admin-user password on Active Directory

View this test on GitHub ↗
Platforms: windows

Detect the Microsoft FIDO authentication disable activities that adversary attempt to gains access to login credentials (e.g., passwords), they may be able to impersonate the user and access sensitive accounts or data and also increases the risk of falling victim to phishing attacks. See the related article (https://admx.help/?Category=Windows_10_2016&Policy=Microsoft.Policies.FidoAuthentication::AllowFidoDeviceSignon).

View this test on GitHub ↗
Platforms: windows

Detect the disable secondary authentication activities that adversary attempt to bypass MFA and to get the unauthorized access to the system or sensitive data. See the related article (https://admx.help/?Category=Windows_10_2016&Policy=Microsoft.Policies.SecondaryAuthenticationFactor::MSSecondaryAuthFactor_AllowSecondaryAuthenticationDevice).

View this test on GitHub ↗
Platforms: windows

Attackers may add a domain to the trusted site zone to bypass defenses. Doing this enables attacks such as c2 over office365. Upon execution, details of the new registry entries will be displayed. Additionally, open Registry Editor to view the modified entry in HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\. https://www.blackhat.com/docs/us-17/wednesday/us-17-Dods-Infecting-The-Enterprise-Abusing-Office365-Powershell-For-Covert-C2.pdf

View this test on GitHub ↗
Platforms: windows

Adfind tool can be used for reconnaissance in an Active directory environment. This example has been documented by ransomware actors enumerating Active Directory Computer Objects reference- http://www.joeware.net/freetools/tools/adfind/, https://www.fireeye.com/blog/threat-research/2019/04/pick-six-intercepting-a-fin6-intrusion.html

View this test on GitHub ↗
View all validating tests on GitHub →

Atomic tests from Atomic Red Team, (c) Red Canary, MIT License. Not affiliated with or endorsed by Red Canary.

News stories naming this group
10 on this site

Ransomware claim data is unverified: RansomLook (CC BY 4.0).

Glossary