G1051 · ATT&CK 19.1 group
Medusa Group
[Medusa Group](https://attack.mitre.org/groups/G1051) has been active since at least 2021 and was initially operated as a closed ransomware group before evolving into a Ransomware-as-a-Service (RaaS) operation. Some reporting indicates that certain attacks may still be conducted directly by the ransomware’s core developers. Public sources have also referred to the group as “Spearwing” or “Medusa Actors.” (Citation: CISA Medusa Group Medusa Ransomware March 2025) (Citation: Broadcom Medusa Ransomware Medusa Group March 2025) [Medusa Group](https://attack.mitre.org/groups/G1051) employs living-off-the-land techniques, frequently leveraging publicly available tools and common remote management software to conduct operations. The group engages in double extortion tactics, exfiltrating data prior to encryption and threatening to publish stolen information if ransom demands are not met. (Citation: Security Scorecard Medusa Ransomware January 2024) For initial access, [Medusa Group](https://attack.mitre.org/groups/G1051) has exploited publicly known vulnerabilities, conducted phishing campaigns, and used credentials or access purchased from Initial Access Brokers (IABs). The group is opportunistic and has targeted a wide range of sectors globally. (Citation: Intel471 Medusa Ransomware May 2025)
Aliases: Medusa Group
Mapped techniques (57)
Cyber Knowledge routes
These contextual routes explain behaviors associated with this ATT&CK group record. They support learning and investigation planning; they do not add attribution evidence.
Cyber Threat Intelligence (CTI) · explicit-idModule 3 — Core Frameworks Models
Cyber Threat Intelligence (CTI) · explicit-idModule 8 — Operationalizing CTI (CTI → Detection)
Cyber Threat Intelligence (CTI) · explicit-idModule 4 — Detection engineering and detection as code
Blue Team & Defensive Security · explicit-idExploitability validation and laboratory exploit engineering
Vulnerability Research & Exploit Development · explicit-idModule 5 — Threat hunting
Blue Team & Defensive Security · explicit-nameWindows endpoint and identity forensics
Digital Forensics & Incident Response (DFIR) · explicit-nameModule 11 — Mobile and thick-client security
Red Team & Offensive Security · explicit-nameWeakness taxonomy and vulnerability identity
Vulnerability Research & Exploit Development · topic-matchData classification, storage, cryptography, keys, backup, and deletion
Cloud Security · topic-matchCloud logging, detection engineering, ATT CK, and response automation
Cloud Security · topic-matchEmbedded, firmware, hardware, and update-chain research
Vulnerability Research & Exploit Development · topic-match