◇ SIGN IN
← all actors
ransomware

Medusa

activemedium confidence
Ransomware
MedusaSpearwing (assessed cluster)Storm-1175-linked (assessed)
Attribution
RaaS (financially motivated, unattributed)
Origin
Unknown
First seen
2021
Last active
2026
Motivation
Financially motivated (ransomware)
Confidence
medium
MENA targeting
Saudi Arabia, UAE, Morocco
Sectors
Agriculture/food, construction, financial services, transport/logistics

Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.

Why it mattersRansomware actor, medium confidence, documented targeting Saudi Arabia, UAE, Morocco (Agriculture/food, construction, financial services sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.

Medusa is a double-extortion ransomware-as-a-service operation active since 2021, documented by CISA/FBI as having affected over 300 victims, and distinct from the older MedusaLocker family and the Medusa Android trojan.

History

Medusa began around 2021 as a closed variant and later evolved into a RaaS. It conducts double-extortion attacks, exfiltrating data before encryption and threatening publication on its leak site. In March 2025 the FBI, CISA and MS-ISAC published advisory AA25-071A, documenting more than 300 victims across healthcare, education, legal, insurance, technology and manufacturing, based on activity investigated as recently as February 2025. FBI investigation stresses that this Medusa ransomware is unrelated to the older MedusaLocker family and to the Medusa mobile banking trojan.

Into 2026, activity attributed to Medusa deployment continued, including Microsoft reporting on Storm-1175 delivering Medusa in high-tempo operations against vulnerable web-facing systems.

Medusa's leak site has listed victims in Saudi Arabia, the UAE and Morocco among its international claims. These listings are extortion allegations and should be treated as claims, not confirmed breaches, unless independently verified.

Notable campaigns

2025
CISA advisory AA25-071A
FBI/CISA/MS-ISAC documented 300+ Medusa victims across multiple sectors as of February 2025.
2026
Storm-1175 web-facing exploitation
Microsoft reported Storm-1175 deploying Medusa against vulnerable internet-facing systems (assessed).
2025
MENA leak-site listings
Saudi, UAE and Moroccan organizations appeared on Medusa's leak site (claimed, not independently confirmed).

Claimed victims · 517 tracked

Leak-site postings via ransomware.live — claimed by the group, not confirmed breaches. Metadata only. MENA Ransomware Watch →

Claim volume · last 12 months
SONDJFMAMJJA
DateVictimCountrySector
Comune di BattipagliaITGovernment & Defense
MESA ProductsUSManufacturing
Grandview Family MedicineUSHealthcare
South Hays Fire DepartmentUSGovernment & Defense
Balloons EverywhereUSRetail & E-Commerce
Resource Corporation of AmericaUSHealthcare
JBSUSHealthcare
Callipo GroupITAgriculture and Food Production
Shamrock TechnologiesUSTechnology
Sampoerna AgroIDAgriculture and Food Production
Thunder Bay CounsellingCAGovernment & Defense
Concord AcademyUSEducation