Medusa Group
Reports per quarter
Techniques seen in the last two years
- T1027 2 reports reports only
- T1190 2 reports in ATT&CK
- T1219 2 reports in ATT&CK
- T1003 1 report reports only
- T1003.001 1 report in ATT&CK
- T1014 1 report reports only
- T1016 1 report in ATT&CK
- T1021.001 1 report in ATT&CK
- T1027.013 1 report reports only
- T1036.005 1 report reports only
Show all 48 techniques Show fewer
- T1041 1 report reports only
- T1046 1 report in ATT&CK
- T1047 1 report in ATT&CK
- T1055.009 1 report reports only
- T1056 1 report reports only
- T1059.001 1 report in ATT&CK
- T1059.003 1 report in ATT&CK
- T1059.004 1 report reports only
- T1059.008 1 report reports only
- T1069.002 1 report in ATT&CK
- T1070 1 report reports only
- T1070.003 1 report in ATT&CK
- T1071 1 report reports only
- T1071.001 1 report in ATT&CK
- T1072 1 report in ATT&CK
- T1074 1 report reports only
- T1078 1 report in ATT&CK
- T1082 1 report in ATT&CK
- T1083 1 report in ATT&CK
- T1090 1 report reports only
- T1105 1 report in ATT&CK
- T1135 1 report in ATT&CK
- T1136.002 1 report in ATT&CK
- T1140 1 report reports only
- T1203 1 report reports only
- T1205.002 1 report reports only
- T1486 1 report in ATT&CK
- T1489 1 report in ATT&CK
- T1490 1 report in ATT&CK
- T1529 1 report in ATT&CK
- T1547 1 report reports only
- T1563.001 1 report reports only
- T1566 1 report reports only
- T1567.002 1 report in ATT&CK
- T1569.002 1 report in ATT&CK
- T1573 1 report reports only
- T1601 1 report reports only
- T1657 1 report in ATT&CK
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-2018-13379 KEV ransomware
- CVE-2021-21972 KEV ransomware
- CVE-2022-1388 KEV ransomware
- CVE-2022-21999 KEV ransomware
- CVE-2022-2294 KEV ransomware
- CVE-2022-22948 KEV
- CVE-2022-2295
- CVE-2022-41328 KEV
- CVE-2022-42475 KEV ransomware
- CVE-2023-20867 KEV
- CVE-2023-34048 KEV
- CVE-2023-48788 KEV ransomware
Show all 15 CVEs Show fewer
- CVE-2024-1709 KEV ransomware
- CVE-2025-21590 KEV
- CVE-2025-61882 KEV ransomware
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
Show all 41 reports Show fewer
-
Medusa Ransomware: Evolving Tactics in Modern Cyber Extortion
The original link failed its last check. Original publisher Detailsfor Medusa Ransomware: Evolving Tactics in Modern Cyber Extortion
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ransomware review- March 2023
-
Technical Analysis of MedusaLocker Ransomware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Technical Analysis of MedusaLocker Ransomware
-
Flubot- the evolution of a notorious Android Banking Malware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Flubot- the evolution of a notorious Android Banking Malware
-
Tracking Android-Joker payloads with Medusa, static analysis (and patience)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Tracking Android-Joker payloads with Medusa, static analysis (and patience)
-
Medusa- a marriage partner as gunslinger
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Medusa- a marriage partner as gunslinger
-
Mobile Malware- TangleBot Untangled
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Mobile Malware- TangleBot Untangled
-
The Rage of Android Banking Trojans
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Rage of Android Banking Trojans
-
Try not to stare - MedusaLocker at a glance
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Try not to stare - MedusaLocker at a glance
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor MedusaLocker Ransomware
-
MedusaHTTP DDoS Slithers Back into the Spotlight
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor MedusaHTTP DDoS Slithers Back into the Spotlight
-
MedusaHTTP DDoS Slithers Back into the Spotlight | NETSCOUT
The original link failed its last check. Original publisher Detailsfor MedusaHTTP DDoS Slithers Back into the Spotlight | NETSCOUT
-
Doctor Web discovers a botnet that attacks Russian banks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Doctor Web discovers a botnet that attacks Russian banks
Newest first. Details opens the report in Explore.