LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G1051: Medusa Group

Medusa Group has been active since at least 2021 and was initially operated as a closed ransomware group before evolving into a Ransomware-as-a-Service (RaaS) operation. Some reporting indicates that certain attacks may still be conducted directly by the ransomware’s core developers. Public sources have also referred to the group as “Spearwing” or “Medusa Actors.” CitationCISA Medusa Group Medusa Ransomware March 2025 CitationBroadcom Medusa Ransomware Medusa Group March 2025 Medusa Group employs living-off-the-land techniques, frequently leveraging publicly available tools and common remote management software to conduct operations. The group engages in double extortion tactics, exfiltrating data prior to encryption and threatening to publish stolen information if ransom demands are not met. CitationSecurity Scorecard Medusa Ransomware January 2024 For initial access, Medusa Group has exploited publicly known vulnerabilities, conducted phishing campaigns, and used credentials or access purchased from Initial Access Brokers (IABs). The group is opportunistic and has targeted a wide range of sectors globally. CitationIntel471 Medusa Ransomware May 2025

EnterpriseG1051GroupObject v1.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

Medusa Group matters because ATT&CK describes it as a ransomware group that evolved into a Ransomware-as-a-Service operation and uses double extortion: data theft before encryption. For leaders, the decision point is not only “can we stop ransomware,” but whether the organization can prove it can resist credential theft, remote access abuse, living-off-the-land activity, data exfiltration, and rapid lateral movement before encryption begins.

Executive priority

Prioritize this as an operational resilience and incident readiness issue. The ATT&CK relationships point to credential access against LSASS and NTDS, use of valid accounts, RDP, WMI, PsExec, PowerShell/cmd, software deployment tools, and Rclone-style cloud synchronization. Executives should ask whether privileged identity controls, remote administration governance, vulnerability exposure management, egress monitoring, backup recovery, and ransomware communications/legal workflows are tested together—not as separate control checklists.

Technical view

SOC, detection engineering, and IR teams should validate coverage around the behavior chain implied by the relationships: initial access may involve known vulnerabilities, phishing, or purchased credentials; follow-on activity may include discovery, credential dumping, lateral movement over RDP/WMI/PsExec, command execution via PowerShell or Windows command shell, use of legitimate admin/deployment tools, file deletion or command-history clearing, web-protocol C2, Rclone-like exfiltration, and eventual Medusa ransomware execution. Because MITRE provides no dedicated detection text for this group object, detection should be built from the related techniques and tools rather than group-name matching.

Likely telemetry

  • Identity provider, VPN, RDP, and externally exposed service authentication logs, especially successful logins from unusual sources or with privileged accounts
  • Windows endpoint telemetry including process creation, command line, PowerShell activity, WMI activity, service creation, LSASS access, and suspicious access to domain controller credential stores
  • Domain controller and Active Directory audit logs for privileged group enumeration, NTDS-related access, and abnormal administrative authentication paths
  • Remote administration and software deployment tool logs, including PsExec-like execution and centralized deployment activity
  • Network telemetry for internal discovery, service scanning, lateral movement, and unusual web-protocol command-and-control patterns

Detection direction

  • Do not rely on ransomware binary signatures alone; tune for precursor behaviors such as credential dumping, domain discovery, remote execution, and unusual use of legitimate administration tools.
  • Baseline legitimate use of RDP, WMI, PsExec, PowerShell, cmd, certutil, software deployment platforms, and Rclone-like utilities so alerts can focus on abnormal account, host, time, destination, and volume patterns.
  • Correlate valid-account activity with discovery and lateral movement. A single successful login may look benign, but a login followed by domain group enumeration, remote system discovery, service discovery, and remote execution is higher risk.
  • Treat Rclone/cloud-sync style egress as a data-loss and ransomware precursor signal, especially when observed from servers, domain-joined systems, or accounts that do not normally perform bulk transfers.
  • Account for blind spots: unmanaged endpoints, incomplete command-line logging, limited PowerShell visibility, missing domain controller auditing, unmonitored remote management tools, and weak outbound traffic inspection can hide much of the described activity.

Mitigation priorities

  • First reduce initial access exposure: patch publicly known vulnerabilities, harden phishing-resistant access paths where feasible, and review externally exposed remote access services.
  • Strengthen identity controls: enforce MFA for remote access and privileged accounts, limit standing administrative privileges, monitor valid-account abuse, and protect domain controllers and credential stores.
  • Constrain lateral movement: restrict RDP/WMI/PsExec use, segment critical systems, and govern centralized software deployment tools with strong approval, logging, and least privilege.
  • Improve ransomware resilience: maintain protected, tested backups; define recovery priorities; and rehearse incident response decisions for data theft plus encryption scenarios.
  • Limit exfiltration paths: monitor and control unsanctioned cloud storage synchronization tools and unusual outbound transfer volumes while preserving business-approved use cases.
Additional notes and limits

This take is based on ATT&CK group G1051 and its supplied relationships. The strongest defensible interpretation is that Medusa Group represents a ransomware and double-extortion risk pattern involving credential theft, living-off-the-land administration, lateral movement, discovery, exfiltration tooling, and ransomware execution. Local control validation should be mapped to the related techniques and tools, not to the group name alone.

The ATT&CK object lists no platforms or tactics directly for the group and provides no official detection text. Platform references in this take come from the supplied related techniques and software. The object also describes opportunistic targeting across sectors globally, so organization-specific exposure, likelihood, and control effectiveness require local telemetry and asset context.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Medusa Group

Medusa Group has been active since at least 2021 and was initially operated as a closed ransomware group before evolving into a Ransomware-as-a-Service (RaaS) operation. Some reporting indicates that certain attacks may still be conducted directly by the ransomware’s core developers. Public sources have also referred to the group as “Spearwing” or “Medusa Actors.” CitationCISA Medusa Group Medusa Ransomware March 2025 CitationBroadcom Medusa Ransomware Medusa Group March 2025 Medusa Group employs living-off-the-land techniques, frequently leveraging publicly available tools and common remote management software to conduct operations. The group engages in double extortion tactics, exfiltrating data prior to encryption and threatening to publish stolen information if ransom demands are not met. CitationSecurity Scorecard Medusa Ransomware January 2024 For initial access, Medusa Group has exploited publicly known vulnerabilities, conducted phishing campaigns, and used credentials or access purchased from Initial Access Brokers (IABs). The group is opportunistic and has targeted a wide range of sectors globally. CitationIntel471 Medusa Ransomware May 2025

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Relationship explorer

All related ATT&CK context

No relationships are available in the current normalized data for this object.

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.0
Created
Modified
Raw hash
2a3cd4c70af93393...
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.