FlagThis
← Threat Actors
/
Global
/
Medusa Group
DOSSIER // MEDUSA-GROUP
Medusa Group
ACTIVE CAMPAIGN TRACKED
⚠ Critical Threat
Primary Aliases:
G1051
Medusa Actors
Medusa Blog
MedusaLocker
🔍 Adversary Rosetta Stone (7) ▾
📋 Copy All
Sponsor / State Affiliation
Criminal organization
Primary Motivation
Financial extortion
Active Timeline
Unknown – Present
Confidence Rating
85% (Grounded)
Global Healthcare and Manufacturing Extortion Wave, Edge Device Exploitation Campaign
📥 Export ATT&CK Layer (.json)
🔔 RSS Feed
🏛️ CISA Advisories ↗
📋 Copy Dossier Briefing
⚔️ Weaponized CVE Matrix
(0)
No specific weaponized CVEs currently mapped in the public baseline.
🎯 Target Sectors & Focus
Healthcare
Manufacturing
Government
Education
Professional Services
Finance
🛡️ MITRE ATT&CK® Attack Lifecycle
(7 TTPs)
📥 Download Navigator JSON
All Stages
7
Initial Access
2
Credential Access & Discovery
1
Lateral Movement & Collection
1
Command & Control
1
Exfiltration & Impact
1
Operational Techniques
1
Initial Access
2
T1566
Exploitation of Public-Facing Applications
↗
T1566
Vulnerability Exploitation (VPN/Edge Devices)
↗
Credential Access & Discovery
1
T1003
Credential Access via Stealer Logs
↗
Lateral Movement & Collection
1
T1021
Lateral Movement via RDP and PsExec
↗
Command & Control
1
T1071
Exfiltration via Rclone and Mega.nz
↗
Exfiltration & Impact
1
T1485
Double Extortion (Data Leakage)
↗
Operational Techniques
1
T1000
Living off the Land (LotL)
↗
📰 Verified Campaigns & Intelligence Archive
🔔 Subscribe to Alerts
No recent breaking campaign alerts recorded in the FlagThis threat database.
Adversary Rosetta Stone // Medusa Group
×
🛡️ Other Industry Tracking Codes
G1051
📋
Medusa Actors
📋
Medusa Blog
📋
MedusaLocker
📋
Spearwing
📋
Storm-1175
📋
Transforming Scorpius
📋
Copied to clipboard
SHARE INTELLIGENCE WIRE
×
Story Title
X / Twitter
Bluesky
LinkedIn
Copy Link
LINK COPIED TO CLIPBOARD