Medusa

Medusa — Threat Actor Profile | ObscureIQ
ObscureIQ Threat Intelligence · Actor Profile

MedusaConfidence: High

Ransomware (RaaS)
Also known as: Medusa (MedusaLocker-unrelated)

Motivation: Financial

2Attributed Breaches Circulating
HighAttribution Confidence
Ransomware (RaaS)Actor Type

Overview

Pressures victims with double extortion and public-release threats across healthcare, education, technology, manufacturing, legal, and government, prominent through 2023-2025. Russia-aligned (avoids Russia/CIS targets); relies on initial access brokers and phishing. MITRE ATT&CK G1051; CISA advisory AA25-071A.

Tactics, Targeting & TTPs

RaaS with affiliates; relies on initial access brokers and phishing; avoids Russia/CIS targets (Russia-aligned). MITRE ATT&CK G1051; CISA advisory AA25-071A (2025).

Source

Attribution draws on public threat-intelligence reporting · Established (multi-source). Primary source →

Were you exposed in one of these breaches?

Check your exposure privately, or request a tailored exposure audit.

Request Consultation