Medusa Ransomware has leveraged an encoded list of services that it designates for termination.567
tool
Medusa Ransomware S1244
- Type
- malware
- Created
- 17 October 2025
- Last modified
- 21 October 2025
Medusa Ransomware has been utilized in attacks since at least 2021. Medusa Ransomware has been known to be utilized in conjunction with living off the land techniques and remote management software. Medusa Ransomware has been used in campaigns associated with “double extortion” ransomware activity, where data is exfiltrated from victim environments prior to encryption, with threats to publish files if a ransom is not paid. Medusa Ransomware software was initially a closed ransomware variant which later evolved to a Ransomware as a Service (RaaS). Medusa Ransomware has impacted victims from a diverse range of sectors within a multitude of countries, and it is assessed Medusa Ransomware is used in an opportunistic manner.[1][2][3][4]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference S1244
Medusa Ransomware has utilized XOR encrypted strings.89
Medusa Ransomware has utilized an encoded list of the processes that it detects and terminates.101112
Medusa Ransomware has launched PowerShell scripts for execution and defense evasion.1314
Medusa Ransomware has used cmd.exe to execute command on an infected host.1516
Medusa Ransomware has the ability to delete itself after execution.17 Medusa Ransomware also has the ability to delete itself after execution through the command cmd /c ping localhost -n 3 > nul & del.1819
Standing S1244
Reach is how much of ATT&CK this tool touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 825 ATT&CK software entries only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
84th percentile · 84% of 825 ATT&CK software entries have this many Enterprise techniques or fewer.
68th percentile · 68% of 825 ATT&CK software entries have this many tactics spanned or fewer.
61% of the population shares a single value across only 22 distinct values, so a percentile here would rank the tie, not the entity.
85% of the population shares a single value across only 8 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
41st percentile · 59% of 825 ATT&CK software entries have more detection rules per technique.
Detection coverage S1244
982 distinct rules cover the 22 techniques recorded for this tool. The 1045 technique-to-rule mappings resolve to 982 distinct rules, because one rule can cover several techniques. 663 Sigma · 319 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org