Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Medusa Ransomware

53
Global rank
22 infographic chevron month
Month rank
38 infographic chevron week
Week rank
0
IOCs

Medusa is a ransomware malware family targeting businesses and institutions. Medusa encrypts crucial data, rendering it inaccessible, and attempts to pressure users to pay to regain control of their information. The group behind this malicious software hosts a TOR website where it shares the list of the organizations whose infrastructure has been compromised. This malware utilizes various tactics, including exploiting vulnerabilities and employs a unique file extension (".MEDUSA") to mark encrypted files.

Ransomware
Type
Unknown
Origin
1 June, 2021
First seen
2 September, 2026
Last seen

How to analyze Medusa Ransomware with ANY.RUN

Type
Unknown
Origin
1 June, 2021
First seen
2 September, 2026
Last seen

IOCs

IP addresses
188.114.97.3
139.99.85.213
149.154.167.99
107.174.192.179
217.78.234.145
184.86.251.7
208.95.112.1
82.29.67.160
192.169.69.25
79.134.225.70
154.91.34.165
23.59.17.18
88.221.169.205
23.11.41.157
103.171.35.26
104.26.2.16
172.67.68.246
2.16.241.9
57.153.246.3
193.122.6.168
Hashes
cd2c00ce027687ce4a8bdc967f26a8ab82f651c9becd703658ba282ec49702bd
0b4db7a09ee3306e969fe0b32228422f223eb2f71bd5d1ec1a0d9ef16b405c58
82b9db18853a960a88dc865714229eeb57979339be6c49ddecfda0766eec9d4b
9f7a00b7385b15a3155dd0ace08d726f5a3b0196ebb4fb0b0aafebf770bc44e1
a0223b245c2a52e9671fa60bddb32283e43b66c363cc82a9af3663dc055fad3c
084134eab56d3f2b14a3a777c078f7b0119eeba0641af54dac74a00fd367cfa7
5f193196db94f25aef709945465e2d33d18bdad144a39f38b63d82c0364aeeee
2b50529f157707de79a76b39344cd2526eb015b3cda5727cc010537aa3cbf084
2d08a668532bcb703a130a12e07f30c1892633a6752e96c8eb0e9394dbf08da2
e02c7824c6eb8c6d0f17eb05d6fdbbe7b949eb03dac40051e2b86ddf71d905e3
d4f988bc2ff9da0c4abfabdfb89615c429f9092065e63d31cf4ffeb4556b730a
31e20fd59f30f4c9ced391f47e9d03961bc1d8b1dca37cab8f4e745e09708c17
1261ddc68472bc4b4634ab432d4406c47d47065c53bbbe6ebc3b2da13b9bc475
e6cdac967faaeec38d8496525aeac902f6c7df0928b16926ca1bc762dfbed7e4
4fc046af9eb1cbc34a1bef9ef9b06f7fbf99de51941efeac89c5ca12d7682d37
fdd46368879c37e8002fe3cd17bf800a066b3d5a870dce8b8d69d19c4513d485
4b6b88d1bafec13e2f9c700168429d3e79a2f0b005a8b9b71f641f6e1b3f2872
ea80a814d369c094b7789cb643b3dd632a09638808753f9c3d28a7d84bac274e
425e043d47ccff297f459836b1710d78344d643e2acdc6db69ff2d2bbe2ae07b
0497a5101fd331317257bf0b54450113570272ecc498aa97a4154663b3d0a914
Domains
crl.microsoft.com
release-assets.githubusercontent.com
must-directed.gl.at.ply.gg
dontlookhere.com
watson.events.data.microsoft.com
fe3cr.delivery.mp.microsoft.com
t.me
rentry.co
self.events.data.microsoft.com
grabify.link
gstatic.com
s3.timeweb.cloud
ip-api.com
activation-v2.sls.microsoft.com
discord.com
www.microsoft.com
client.wns.windows.com
ocsp.digicert.com
github.com
go.microsoft.com
URLs
https://gateway.discord.gg/?v=9&encording=json
https://t.me/m00f3r
https://steamcommunity.com/profiles/76561199851454339
https://gstatic.com/generate_204
https://api.pcloud.com/listfolder?path=/
https://cloud-api.yandex.net/v1/disk/resources?path=/&limit=500
http://checkip.dyndns.org/
https://api.ipify.org/
http://ip-api.com/json/158.173.162.95
https://c291daa6.pythonanywhere.com/static/sig.jpeg
https://t.me/asdawfq
https://narrathfpt.top/tekq
https://steamcommunity.com/profiles/76561199845513035
http://ip-api.com/line/?fields=hosting
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
https://settings-win.data.microsoft.com/settings/v3.0/onesettings/client?osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&localdeviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&attrdataver=186&osuilocale=en-us&osskuid=48&app=wosc&appver=&isflightingenabled=0&telemetrylevel=1&devicefamily=windows.desktop
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
https://login.live.com/rst2.srf
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
Last Seen at
Last Seen at

Recent blog posts

post image
Release Notes: Faster TI Investigations, Fres...
watchers 1374
comments 0
post image
Triage & Response Bottlenecks Eating into...
watchers 1930
comments 0
post image
Major Cyber Attacks in August 2026: US and EU...
watchers 6441
comments 0

What is malware: Medusa Ransomware?

Medusa Ransomware is a type of malicious software employed by cybercriminals for extortion purposes. This tool is used in offensive campaigns that involve the encryption of critical data belonging to organizations, followed by a ransom demand for its decryption.

Medusa Ransomware first emerged in June 2021 and has since targeted various industries, including the education sector. In 2023 alone, it is reported to have affected over 70 organizations globally, operating under the Ransomware-as-a-Service (RaaS) business model.

The cybercriminals behind Medusa Ransomware maintain a dedicated TOR website where they publish information about their victims, accompanied by a countdown clock indicating the time left before the data is released.

To prevent data leaks, victims are typically presented with three options. They can extend the time limit, pay a fee to have their stolen data deleted, or opt to download the compromised data, essentially buying back their own information.

One notable incident involving Medusa Ransomware took place in 2023. The group successfully infiltrated Toyota's European division, demanding a substantial ransom of $8 million. When negotiations broke down, the attackers proceeded to release the stolen data on their dark web portal.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Medusa ransomware malicious software technical details

One of the primary signs of a Medusa ransomware attack is the addition of the ".MEDUSA" extension to encrypted files. However, this malware has been known to use various other extensions such as .1btc, .mylock, and .key1.

The variety of file extensions linked to Medusa ransomware indicates the existence of several versions. The ransom notes can appear in either TXT or HTML format (in newer versions). The note contains a unique 32-character hash value used for communication with the attackers.

For the encryption process, Medusa utilizes the strong AES256 algorithm, making decryption without the proper key extremely challenging. Additionally, the key used for encryption is itself encrypted using an RSA public key, further securing the encrypted data.

Medusa often infiltrates systems by exploiting existing vulnerabilities. In the past, it has targeted weaknesses such as CVE-2022-2294 and CVE-2022-21999 to deliver its payload.

To maintain persistence on the infected system, Medusa copies an executable file, usually named "svhost.exe" or "svhostt.exe", to a specific directory within the user's profile. This executable is then scheduled to run at regular intervals, ensuring the continued operation of the ransomware.

Medusa targets and terminates processes associated with security software. By doing so, it aims to disable potential detection and data recovery mechanisms.

Another strategy employed by Medusa is the deletion of Volume Shadow Copies, a Windows feature that creates backups of files at specific points in time. By eliminating these copies, Medusa removes a potential recovery method for victims.

Medusa Ransomware execution process

Medusa Ransomware can be analyzed in the ANY.RUN sandbox. To do this, we can upload its sample to the service.

Medusa ransomware typically infiltrates a system through phishing emails or malicious downloads, exploiting vulnerabilities in outdated software or weak security measures. Once executed, it stealthily encrypts files using strong encryption algorithms, rendering them inaccessible to the user. Medusa then displays a ransom note, usually demanding payment in cryptocurrency, in exchange for a decryption key. The ransom note often includes instructions on how to make the payment and how to contact the attackers. Meanwhile, Medusa may also attempt to spread laterally across the network, infecting other connected devices. Finally, the attackers await payment confirmation before providing the decryption key, although there's no guarantee they will uphold their end of the bargain. As a common activity for ransomware, Medusa halts system services and deletes shadow volumes.

Medusa ransom note shown in ANY.RUN Medusa ransom note demonstrated in ANY.RUN

Medusa Ransomware malware distribution methods

Similar to other malware, such as AsyncRAT and Remcos, phishing is one of the primary distribution methods employed by Medusa ransomware operators. Attackers send deceptive emails to potential victims, often disguising themselves as legitimate organizations or individuals. These emails typically contain malicious attachments or links, which, when clicked or downloaded, initiate the ransomware installation process.

Conclusion

Medusa ransomware's ability to compromise sensitive data poses a threat to businesses and individuals. The consequences of a successful attack can be severe, ranging from financial losses due to ransom demands to reputational damage caused by leaked information. Prioritizing preventive measures, such as learning about the malware’s TTPs and collecting its indicators of compromise (IOCs) can prove invaluable for any organization’s security posture. ANY.RUN is an online sandbox that enables users to do just that.

This interactive sandbox environment allows users to safely explore potential malware and quickly receive detailed technical reports. By leveraging this service, users can collect important information for making decisions needed for safeguarding their systems from harm.

Create your ANY.RUN account – it’s free!

HAVE A LOOK AT

Spynote screenshot
Spynote
spynote
SpyNote, also known as SpyMax and CypherRat, is a powerful Android malware family designed primarily for surveillance and data theft, often categorized as a Remote Access Trojan (RAT). Originally emerged in 2016, SpyNote has evolved significantly, with new variants continuing to appear as recently as 2023–2025.
Read More
BlackMoon screenshot
BlackMoon
blackmoon
BlackMoon also known as KrBanker is a trojan aimed at stealing payment credentials. It specializes in man-in-the-browser (MitB) attacks, web injection, and credential theft to compromise users' online banking accounts. It was first noticed in early 2014 attacking banks in South Korea and has impressively evolved since by adding a number of new infiltration techniques and information stealing methods.
Read More
Stealer screenshot
Stealer
stealer
Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.
Read More
Qilin Ransomware screenshot
Qilin ransomware (predecessor known as “Agenda”) is a rapidly evolving ransomware-as-a-service (RaaS) operation targeting organizations worldwide. Known for double extortion tactics (encrypting files while also threatening to leak stolen data) Qilin has quickly gained notoriety for its customization, flexibility, and impact on critical infrastructure.
Read More
Trojan screenshot
Trojan
trojan trojan horse
Trojans are a group of malicious programs distinguished by their ability to masquerade as benign software. Depending on their type, trojans possess a variety of capabilities, ranging from maintaining full remote control over the victim’s machine to stealing data and files, as well as dropping other malware. At the same time, the main functionality of each trojan family can differ significantly depending on its type. The most common trojan infection chain starts with a phishing email.
Read More
PureCrypter screenshot
PureCrypter
purecrypter
First identified in March 2021, PureCrypter is a .NET-based loader that employs obfuscation techniques, such as SmartAssembly, to evade detection. It has been used to distribute malware families including AgentTesla, RedLine Stealer, and SnakeKeylogger. The malware is typically delivered through phishing campaigns and malicious downloads, often masquerading as legitimate files with extensions like .mp4 or .pdf. PureCrypter utilizes encryption and compression to conceal its payloads and can inject malicious code into legitimate processes to maintain persistence on the infected system.
Read More