Medusa is a ransomware-as-a-service operation active since June 2021 that has targeted over 300 victims across critical infrastructure sectors including healthcare, education, legal, and manufacturing using double-extortion, with attacks surging 42% between 2023 and 2024 and a formal CISA advisory issued in early 2025.
AES-256 encryption with RSA key wrapping
Deletes shadow copies via vssadmin and wmic
Stops security and backup services
Brute-forces RDP for initial access
Uses purchased or brute-forced credentials