Ransomware Group intelligence
Medusa
InactiveTrack Medusa with 521 published victims and 12 known leak locations in a single intelligence view.
Overview
Medusa is tracked by Breach House as a ransomware group with 521 published victims.
United States is currently the most targeted country in this dataset.
12 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (12)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 10 | Onion service | Down checked 2h ago | hupxs7ps7md24kpz4lwsbra64abgxjx3pcc2wuca5ibawf2g5hlpfyqd.onion |
| Leak location 8 | Onion service | Down checked 2h ago | cx5u7zxbvrfyoj6ughw76oa264ucuuizmmzypwum6ear7pct4yc723qd.onion |
| Leak location 6 | Onion service | Down checked 2h ago | s7lmmhlt3iwnwirxvgjidl6omcblvw2rg75txjfduy73kx5brlmiulad.onion |
| Leak location 12 | Onion service | Down checked 2h ago | 7aqabivkwmpvjkyefonf3gpy5gsubopqni7kcirsrq3pflckxq5zz4id.onion |
| Leak location 11 | Onion service | Down checked 2h ago | 62foekhv5humjrfwjdyd2dgextpbf5i7obguhwvfoghmu3nxpkmxlcid.onion |
| Leak location 4 | Onion service | Down checked 2h ago | dlmfciajg5s4vliyo5dhs5jyzhi2xr2fnkebul46lpf4xudtqiue4nid.onion |
| Leak location 7 | Web location | Down checked 2h ago | 45.9.148.39 |
| Leak location 5 | Onion service | Down checked 2h ago | kyfiw76eol6ph2mq7pi5e5tdvce37bicddhai62qhdc5ja6jdchz4qqd.onion |
| Leak location 3 | Onion service | Down checked 2h ago | xfv4jzckytb4g3ckwemcny3ihv4i5p4lqzdpi624cxisu35my5fwi5qd.onion |
| Leak location 9 | Onion service | Down checked 2h ago | xfv4jzckytb4g3ckwemcny3ihv4i5p4lqzdpi624cxisu35my5fwi5qd.onion |
| Leak location 2 | Onion service | Down checked 2h ago | medusakxxtp3uo7vusntvubnytaph4d3amxivbggl3hnhpk2nmus34yd.onion |
| Leak location 1 | Onion service | Down checked 2h ago | medusaxko7jxtrojdkxo66j7ck4q5tgktf7uqsqyfry4ebnxlcbkccyd.onion |
Top Activity Sectors (17)
- Communication / Marketing 105
- Services 55
- Public Sector 54
- Healthcare / Pharma 52
- Education 40
- Finance / Legal / Insurance 32
- Construction / Real Estate 31
- IT 30
- Manufacturing / Engineering 28
- Retail / E-commerce 20
- Hospitality / Food & Beverage / Tourism 17
- Energy 13
- Transportation / Travel / Logistics 13
- Agriculture / Food 9
- NGOs / Associations 7
- Telecommunications 6
- Not identified 4
Typical Attacks (64)
▼How Medusa typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via Medusa Group, Medusa Ransomware.
-
T1583.006 Web Services Resource Development
What they do: Medusa Group has utilized a file hosting service named filemail[.]com to host a zip file that contained malicious payloads that facilitated follow-on actions.
What that means: Adversaries may register for web services that can be used during targeting.
-
T1585.001 Social Media Accounts Resource Development
What they do: Medusa Group has created social media accounts including Telegram and X to publicize their activities.
What that means: Adversaries may create and cultivate social media accounts that can be used during targeting.
-
T1585.002 Email Accounts Resource Development
What they do: Medusa Group has created email accounts used in ransomware negotiations.
What that means: Adversaries may create email accounts that can be used during targeting.
-
T1588.002 Tool Resource Development
What they do: Medusa Group has obtained and leveraged numerous RMM services, along with publicly available tools used for scanning.
What that means: Adversaries may buy, steal, or download software tools that can be used during targeting.
-
T1608.002 Upload Tool Resource Development
What they do: Medusa Group has utilized a file hosting service called filemail[.]com to host a zip file that contained a RMM service such as ConnectWise.
What that means: Adversaries may upload tools to third-party or adversary controlled infrastructure to make it accessible during targeting.
-
T1650 Acquire Access Resource Development
What they do: Medusa Group has purchased user credentials and other sensitive data from Initial Access Brokers (IABs).
What that means: Adversaries may purchase or otherwise acquire an existing access to a target system or network.
-
What they do: Medusa Group has utilized compromised legitimate local and domain accounts within the victim environment to facilitate remote access and lateral movement sometimes in combination with PsExec.
What that means: Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
-
T1190 Exploit Public-Facing Application Initial Access
What they do: Medusa Group has leveraged public facing vulnerabilities in their campaigns against victim organizations to gain initial access.
What that means: Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
-
T1047 Windows Management Instrumentation Execution
What they do: Medusa Group has utilized Windows Management Instrumentation to query system information.
What that means: Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads.
-
T1059.001 PowerShell Execution
What they do: Medusa Group has leveraged PowerShell for execution and defense evasion.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1059.003 Windows Command Shell Execution
What they do: Medusa Group has used Windows Command Prompt to control and execute commands on the system to include ingress, network, and filesystem enumeration activities.
What that means: Adversaries may abuse the Windows command shell for execution.
-
What they do: Medusa Group has utilized software deployment and management solutions to deploy their encryption payload to include BigFix and PDQ Deploy.
What that means: Adversaries may gain access to and use centralized software suites installed within an enterprise to execute commands and move laterally through the network.
-
T1106 Native API Execution
What they do: Medusa Group has leveraged Windows Native API functions to execute payloads.
What that means: Adversaries may interact with the native OS application programming interface (API) to execute behaviors.
-
T1559 Inter-Process Communication Execution
What they do: Medusa Ransomware has leveraged the `CreatePipe` API to enable inter-process communication.
What that means: Adversaries may abuse inter-process communication (IPC) mechanisms for local code or command execution.
-
T1559.001 Component Object Model Execution
What they do: Medusa Group has leveraged Component Object Model (COM) to bypass UAC.
What that means: Adversaries may use the Windows Component Object Model (COM) for local code execution.
-
T1569.002 Service Execution Execution
What they do: Medusa Group has utilized PsExec to execute scripts and commands within victim environments.
What that means: Adversaries may abuse the Windows service control manager to execute malicious commands or payloads.
-
What they do: Medusa Group has modified Registry keys to elevate privileges, maintain persistence and allow remote access.
What that means: Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
-
T1136.002 Domain Account Persistence
What they do: Medusa Group has created a domain account within the victim environment.
What that means: Adversaries may create a domain account to maintain access to victim systems.
-
T1505.003 Web Shell Persistence
What they do: Medusa Group has utilized webshells to an exploited Microsoft Exchange Server.
What that means: Adversaries may backdoor web servers with web shells to establish persistent access to systems.
-
What they do: Medusa Group has used vulnerable or signed drivers to modify security solutions on victim devices.
What that means: Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence.
-
T1548.002 Bypass User Account Control Privilege Escalation
What they do: Medusa Group has attempted to bypass UAC using Component Object Model (COM) interface.
What that means: Adversaries may bypass UAC mechanisms to elevate process privileges on system.
-
T1027.002 Software Packing Stealth
What they do: Medusa Group has packed the code of dropped kernel drivers using the packer ASM Guard.
What that means: Adversaries may perform software packing or virtual machine software protection to conceal their code.
-
T1027.010 Command Obfuscation Stealth
What they do: Medusa Group has obfuscated PowerShell scripts with Base64 encoding.
What that means: Adversaries may obfuscate content during command execution to impede detection.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: Medusa Ransomware has utilized XOR encrypted strings.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1070.003 Clear Command History Stealth
What they do: Medusa Group has cleared command history by running the PowerShell command `Remove-Item (Get-PSReadlineOption).HistorySavePath`.
What that means: In addition to clearing system logs, an adversary may clear the command history of a compromised account to conceal the actions undertaken during an intrusion.
-
T1070.004 File Deletion Stealth
What they do: Medusa Group has deleted previously installed tools.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1140 Deobfuscate/Decode Files or Information Stealth
What they do: Medusa Ransomware has decoded XOR encrypted strings prior to execution in memory.
What that means: Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis.
-
T1218.014 MMC Stealth
What they do: Medusa Group has leveraged Microsoft Management Console (MMC) to facilitate lateral movement and to interact locally or remotely with victim devices using the command `mmc.exe compmgmt.msc /computer:{hostname/ip}`.
What that means: Adversaries may abuse mmc.exe to proxy execution of malicious .msc files.
-
T1564.003 Hidden Window Stealth
What they do: Medusa Group has utilized the `ShowWindow` API function to hide the current window.
What that means: Adversaries may use hidden windows to conceal malicious activity from the plain sight of users.
-
T1679 Selective Exclusion Stealth
What they do: Medusa Ransomware has avoided specified files, file extensions and folders to ensure successful execution of the payload and continued operations of the impacted device.
What that means: Adversaries may intentionally exclude certain files, folders, directories, file types, or system components from encryption or tampering during a ransomware or malicious payload execution.
-
T1553.002 Code Signing Defense Impairment
What they do: Medusa Group has utilized vulnerable or signed drivers to kill or delete services associated with endpoint detection and response (EDR) tools.
What that means: Adversaries may create, acquire, or steal code signing materials to sign their malware or tools.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: Medusa Group has terminated antivirus services utilizing the gaze.exe executable and utilizing `psexec.exe`.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1686 Disable or Modify System Firewall Defense Impairment
What they do: Medusa Group has utilized PsExec to execute batch scripts that modify firewall settings.
What that means: Adversaries may disable or modify host-based or network firewalls to impair defensive mechanisms and enable further action.
-
T1690 Prevent Command History Logging Defense Impairment
What they do: Medusa Group has removed PowerShell command history through the use of the PSReadLine module by running the PowerShell command `Remove-Item (Get-PSReadlineOption).HistorySavePath`.
What that means: Adversaries may impair command history logging to hide commands they run on a compromised system.
-
T1003.001 LSASS Memory Credential Access
What they do: Medusa Group has leveraged Mimikatz to dump LSASS to harvest credentials.
What that means: Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS).
-
T1003.003 NTDS Credential Access
What they do: Medusa Group has accessed the ntds.dit file to engage in credential dumping.
What that means: Adversaries may attempt to access or create a copy of the Active Directory domain database in order to steal credential information, as well as obtain other information about domain members such as devices, users, and access rights.
-
T1007 System Service Discovery Discovery
What they do: Medusa Ransomware has leveraged an encoded list of services that it designates for termination.
What that means: Adversaries may try to gather information about registered local system services.
-
T1016 System Network Configuration Discovery Discovery
What they do: Medusa Group has obtained host network details utilizing the command `cmd.exe /c ipconfig /all`.
What that means: Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through information discovery of remote systems.
-
T1018 Remote System Discovery Discovery
What they do: Medusa Group has used PDQ Inventory to get an inventory of the endpoints on the network.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1033 System Owner/User Discovery Discovery
What they do: Medusa Group has utilized PsExec to execute `quser` to discover the user session information.
What that means: Adversaries may attempt to identify the primary user, currently logged in user, set of users that commonly uses a system, or whether a user is actively using the system.
-
T1046 Network Service Discovery Discovery
What they do: Medusa Group has the capability to use living off the land (LOTL) binaries to perform network enumeration.
What that means: Adversaries may attempt to get a listing of services running on remote hosts and local network infrastructure devices, including those that may be vulnerable to remote software exploitation.
-
T1057 Process Discovery Discovery
What they do: Medusa Group has utilized a hard-coded security tool process list that identifies and terminates using an undocumented IOCTL code 0x222094.
What that means: Adversaries may attempt to get information about running processes on a system.
-
T1069.002 Domain Groups Discovery
What they do: Medusa Group has utilized the `net group` command to query domain groups within the victim environment.
What that means: Adversaries may attempt to find domain-level groups and permission settings.
-
T1082 System Information Discovery Discovery
What they do: Medusa Group has leveraged `cmd.exe` to identify system info `cmd.exe /c systeminfo`.
What that means: An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture.
-
T1083 File and Directory Discovery Discovery
What they do: Medusa Group has searched for files within the victim environment for encryption and exfiltration.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1087.001 Local Account Discovery
What they do: Medusa Group has leveraged `net user` for account discovery.
What that means: Adversaries may attempt to get a listing of local system accounts.
-
T1124 System Time Discovery Discovery
What they do: Medusa Ransomware has discovered device uptime through `GetTickCount()`.
What that means: An adversary may gather the system time and/or time zone settings from a local or remote system.
-
T1135 Network Share Discovery Discovery
What they do: Medusa Group has identified network shares using `cmd.exe /c net share`.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1518.001 Security Software Discovery Discovery
What they do: Medusa Group has detected security solutions for termination or deletion within the victim device using hard-coded lists of strings containing security product executables.
What that means: Adversaries may attempt to get a listing of security software, configurations, defensive tools, and sensors that are installed on a system or in a cloud environment.
-
T1652 Device Driver Discovery Discovery
What they do: Medusa Group has queried drivers on the victim device through the command `driverquery`.
What that means: Adversaries may attempt to enumerate local device drivers on a victim host.
-
T1680 Local Storage Discovery Discovery
What they do: Medusa Ransomware has enumerated logical drives on infected hosts.
What that means: Adversaries may enumerate local drives, disks, and/or volumes and their attributes like total or free space and volume serial number.
-
T1021.001 Remote Desktop Protocol Lateral Movement
What they do: Medusa Group has used RDP to conduct lateral movement and exfiltrate data.
What that means: Adversaries may use Valid Accounts to log into a computer using the Remote Desktop Protocol (RDP).
-
T1570 Lateral Tool Transfer Lateral Movement
What they do: Medusa Group has utilized legitimate software services such as PDQ Deploy to transfer malicious binaries and tools to other victimized hosts within the target environment.
What that means: Adversaries may transfer tools or other files between systems in a compromised environment.
-
T1071.001 Web Protocols Command and Control
What they do: Medusa Group has communicated through reverse or bind shells over port 443 (HTTPS).
What that means: Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic.
-
T1090.003 Multi-hop Proxy Command and Control
What they do: Medusa Group has used TOR nodes for communications.
What that means: Adversaries may chain together multiple proxies to disguise the source of malicious traffic.
-
T1105 Ingress Tool Transfer Command and Control
What they do: Medusa Group has leveraged certutil, PowerShell, and Windows Command to download additional tools to include RMM services.
What that means: Adversaries may transfer tools or other files from an external system into a compromised environment.
-
T1219 Remote Access Tools Command and Control
What they do: Medusa Group has leveraged Remote Access Software for lateral movement and data exfiltration.
What that means: An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network.
-
T1573.002 Asymmetric Cryptography Command and Control
What they do: Medusa Group has used HTTPS for command and control.
What that means: Adversaries may employ a known asymmetric encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol.
-
T1567.002 Exfiltration to Cloud Storage Exfiltration
What they do: Medusa Group has utilized Rclone to exfiltrate data from victim environments to cloud storage.
What that means: Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: Medusa Group has encrypted files using AES-256 encryption which then appends the file extension “.medusa” to encrypted files and leaves a ransomware note named “!READ_ME_MEDUSA!!!.txt.”
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1489 Service Stop Impact
What they do: Medusa Group has terminated services related to backups, security, databases, communication, filesharing and websites.
What that means: Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
-
T1490 Inhibit System Recovery Impact
What they do: Medusa Group has deleted recovery files such as shadow copies using `vssadmin.exe`.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
-
T1529 System Shutdown/Reboot Impact
What they do: Medusa Group has manually turned off and encrypted virtual machines.
What that means: Adversaries may shutdown/reboot systems to interrupt access to, or aid in the destruction of, those systems.
-
T1657 Financial Theft Impact
What they do: Medusa Group has stolen and encrypted victims' data in order to extort victims into paying a ransom.
What that means: Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims.
Tools Observed (27)
▼Software Medusa has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Credential theft
Defense evasion
Discovery & enumeration
Exfiltration
LOLBAS (living-off-the-land binaries)
Networking & tunnelling
Remote monitoring & management
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Ransom Notes (2)
▼The note this group leaves on a compromised machine. Click a filename to read it.
!!!READ_ME_MEDUSA!!!.txt
$$\ $$\ $$$$$$$$\ $$$$$$$\ $$\ $$\ $$$$$$\ $$$$$$\ $$$\ $$$ |$$ _____|$$ __$$\ $$ | $$ |$$ __$$\ $$ __$$\ $$$$\ $$$$ |$$ | $$ | $$ |$$ | $$ |$$ / \__|$$ / $$ | $$\$$\$$ $$ |$$$$$\ $$ | $$ |$$ | $$ |\$$$$$$\ $$$$$$$$ | $$ \$$$ $$ |$$ __| $$ | $$ |$$ | $$ | \____$$\ $$ __$$ | $$ |\$ /$$ |$$ | $$ | $$ |$$ | $$ |$$\ $$ |$$ | $$ | $$ | \_/ $$ |$$$$$$$$\ $$$$$$$ |\$$$$$$ |\$$$$$$ |$$ | $$ | \__| \__|\________|\_______/ \______/ \______/ \__| \__| -----------------------------[ Hello, [snip] !!! ]-------------------------- WHAT HAPPEND? ------------------------------------------------------------ 1. We have PENETRATE your network and COPIED data. * We have penetrated entire network including backup system and researched all about your data. * And we have extracted all of your networks including sub offices and your service clients networks valuable data and copied them to private cloud storage. 2. We have ENCRYPTED some your files. While you are reading this message, it means you found your files and data has been ENCRYPTED by world's strongest ransomware. We have access to all of your sub offices and client service networks but didn't lock them all for your brand and privacy. We can solve this issue sliently and smoothly without 3rd parties and we decided lock only some of your main network only. But don't worry, we can restore everything to the original without harming your business. There is only one possible way to get back your systems and business - CONTACT us via LIVE CHAT and pay for the special MEDUSA DECRYPTOR and DECRYPTION KEYs, Data deletion, Keep silent in media. This MEDUSA DECRYPTOR will restore your entire network, This will take less than 1 business day. WHAT GUARANTEES? --------------------------------------------------------------- We can post your data to the public and send emails to your customers. We have professional OSINTs and media team for leak data to telegram, facebook, twitter channels and top news websites. Have a look about us on twitter. You can suffer significant problems due disastrous consequences, leading to loss of valuable intellectual property and other sensitive information, costly incident response efforts, information misuse/abuse, loss of customer trust, brand and reputational damage, legal and regulatory issues. After paying for the data breach and decryption, we guarantee that your data will never be leaked and this is also for our reputation. YOU should be AWARE! --------------------------------------------------------------- If you're not in main chile office, inform your supervisors and stay calm! We will speak only with an authorized person. It can be the CEO, top management, etc. In case you are not such a person - DON'T CONTACT US! Your decisions and action can result in serious harm to your company! If you do not contact us within 3 days, We will start publish your case to our official blog and everybody will start notice your incident! If you do not contact us within 5 days, We will start publish your case and leak video on all social channels and send emails to your customers! --------------------[ Official blog tor address ]-------------------- Using TOR Browser(https://www.torproject.org/download/): http://medusaxko7jxtrojdkxo66j7ck4q5tgktf7uqsqyfry4ebnxlcbkccyd.onion/ CONTACT US! ----------------------[ Your company live chat address ]--------------------------- Using TOR Browser(https://www.torproject.org/download/): http://medusakxxtp3uo7vusntvubnytaph4d3amxivbggl3hnhpk2nmus34yd.onion/[snip] Or Use Tox Chat Program(https://qtox.github.io/) Add user with our tox ID and wait 24h : 4AE245548F2A225882951FB14E9BF87EE01A0C10AE159B99D1EA62620D91A372205227254A9F Our support email: ( [email protected] ) Company identification hash: [snip]
!!!READ_ME_MEDUSA!!!_2.txt
$$\ $$\ $$$$$$$$\ $$$$$$$\ $$\ $$\ $$$$$$\ $$$$$$\ $$$\ $$$ |$$ _____|$$ __$$\ $$ | $$ |$$ __$$\ $$ __$$\ $$$$\ $$$$ |$$ | $$ | $$ |$$ | $$ |$$ / \__|$$ / $$ | $$\$$\$$ $$ |$$$$$\ $$ | $$ |$$ | $$ |\$$$$$$\ $$$$$$$$ | $$ \$$$ $$ |$$ __| $$ | $$ |$$ | $$ | \____$$\ $$ __$$ | $$ |\$ /$$ |$$ | $$ | $$ |$$ | $$ |$$\ $$ |$$ | $$ | $$ | \_/ $$ |$$$$$$$$\ $$$$$$$ |\$$$$$$ |\$$$$$$ |$$ | $$ | \__| \__|\________|\_______/ \______/ \______/ \__| \__| -----------------------------[ Hello, [snip] !!! ]-------------------------- Sorry to interrupt your busy business. WHAT HAPPEND? ------------------------------------------------------------ 1. We have PENETRATE your network and COPIED data. We have penetrated your entire network and researched all about your data. And we have copied all of your confidential data and uploaded to private storage. * You're running a highly valued business and your data was very crucial. 2. We have ENCRYPTED your files. While you are reading this message, it means your files and data has been ENCRYPTED by world's strongest ransomware. Your files have encrypted with new military-grade encryption algorithm and you can not decrypt your files. But don't worry, we can decrypt your files. There is only one possible way to get back your computers and servers, keep your privacy safe - CONTACT us via LIVE CHAT and pay for the special MEDUSA DECRYPTOR and DECRYPTION KEYs. This MEDUSA DECRYPTOR will restore your entire network within less than 1 business day. WHAT GUARANTEES? --------------------------------------------------------------- We can post all of your critial data to the public and send emails to your competitors. We have professional OSINTs and media team for leak data to telegram, facebook, twitter channels and top news websites. You can easily search about us. You can suffer significant problems due to disastrous consequences, leading to loss of valuable intellectual property and other sensitive information, costly incident response efforts, information misuse/abuse, loss of customer trust, brand and reputational damage, and legal and regulatory issues. After paying for the data breach and decryption, we guarantee that your data will never be leaked and make everything silent, this is also for our reputation. YOU should be AWARE! --------------------------------------------------------------- We will speak only with an authorized person. It can be the CEO, top management etc. In case you ar not such a person - DON'T CONTACT US! Your decisions and action can result in serious harm to your company! Inform your supervisors and stay calm! If you do not contact us within 48 hours, We will start publish your case to our official blog and everybody will start notice your incident! --------------------[ Telegram channel ]-------------------- https://t.me/+yXOcSjVjI9tjM2E0 --------------------[ Official blog tor address ]-------------------- Using TOR Browser(https://www.torproject.org/download/): http://xfv4jzckytb4g3ckwemcny3ihv4i5p4lqzdpi624cxisu35my5fwi5qd.onion/ http://cx5u7zxbvrfyoj6ughw76oa264ucuuizmmzypwum6ear7pct4yc723qd.onion/ CONTACT US! ----------------------[ Your company live chat address ]--------------------------- Using TOR Browser(https://www.torproject.org/download/): http://uyku4o2yg34ekvjtszg6gu7cvjzm6hyszhtu7c55iyuzhpr4k5knewyd.onion/[snip] Backup Mirrors: http://5ar4vuckm3k7osdlzskqkaqmqr4jjpmdikuotmlpkrbsxx7ard3xetyd.onion/[snip] --------------------[ Or Use Tox Chat Program(https://utox.org/uTox_win64.exe) ]-------------------- Add user with our tox ID : 061AA6BDE8F6DE6C92F0D6E077359BF6911FCAF80030E82B3A3DB65E63C8011343D34F956FEC Our support email: ( [email protected] ) Company identification hash: [snip]
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (521)
Search, filter and paginate the victim timeline for Medusa. Showing 501–521 of 521.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | The Institute of Space Technology id32039 View details | Pakistan | — | ||
|
The Institute of Space Technology (also known as IST) is a public university located in Islamabad, Pakistan. IST space program aims at designing, building, launching and succesfully operating the Pico-Satellite standard CubeSat. The program is led by Communication Systems Engineering (CSE). Established in 2002 under the auspices of the Pakistan National Space Agency. IST offers a wide array of undergraduate and graduate degrees in partnership of Beihang University and University of Surrey. |
|||||
| Ransomware | Kenya Airports Authority id5553 View details | Kenya | Transportation / Travel / Logistics | ||
|
Kenya Airports Authority (KAA) is the owner and operator of nine civilian airports and airstrips in Kenya. Kenya Airports Authority was established by an act of Parliament in 1992, by the ruling Kenya African National Union government. The KAA Act, Cap 395, provides for the powers and functions of the Authority. Its head office is on the property of Jomo Kenyatta International Airport in Embakasi, Nairobi. |
|||||
| Ransomware | RAYAB Consulting Engineers id5513 View details | Iran, Islamic Republic of | Services | ||
|
RAYAB Consulting Engineers Company was founded in 1984. Taking advantage of hundreds of experienced experts’ cooperation , know – how and scientific experiences, the company has studied , designed and supervised, water and water transmission infrastructural projects, consulting and studying services for potable, agricultural and industrial water consumption, urban and industrial water distribution and wastewater collecting and disposal networks, water and wastewater treatment plants, environmental and health services and water resources conservation as large and small projects throughout Iran In addition to offices in Tehran, it has offices in Isfahan , Ghazvin, Takestan, Gorgan, Karaj, Ghom, Kashan, Delijan, Malayer , Ilaam , Ahwaz, Dezful, Babolsar, Bojnourd, Mashhad, Esfarayen, Kashmar, Birjand, Bandarabbas, Sirjan and Sare – Pole – Zahab |
|||||
| Ransomware | Moose, Martin, Haynes & Lundy id5512 View details | Services | |||
|
For years, Moose, Martin, Haynes & Lundy, P.A. has been providing quality, personalized financial guidance to local individuals and businesses. Our expertise ranges from basic tax management and accounting services to more in-depth services such as audits, financia |
|||||
| Ransomware | International Center of Photography id5491 View details | Services | |||
|
New York, 374 Employees. The International Center of Photography is the world's leading institution dedicated to photography and visual culture. Cornell Capa founded ICP in 1974 to champion "concerned photography"-socially and politically minded images that can educate and change the world |
|||||
| Ransomware | AP Emissions Technologies id5467 View details | United States | IT | ||
|
Automotive Parts · North Carolina, United States AP® Emissions Technologies is one of the leading manufacturers and suppliers of automotive, light truck, and heavy-duty exhaust and emissions products under the AP®, DuraFit®, Eastern Catalytic®, CATCO ®, ANSA®, Cherry Bomb®, DieselTech™, DuraFit™, Maremont®, XLERA and much more. |
|||||
| Ransomware | Foamtec International id5454 View details | IT | |||
|
The best of East and West - that is the strength of Foamtec International. Combining Western cutting edge technology with Eastern traditions of dedicated customer service, Foamex Asia was established in 1997 as a joint venture between Foamex International Inc. |
|||||
| Ransomware | PetroChina Indonesia id5448 View details | Indonesia | Energy | ||
|
PetroChina Indonesia is a company that operates in the Oil & Energy industry. It employs 251-500 people and has $25M-$50M of revenue. The company is headquartered in Jakarta, Jakarta, Indonesia |
|||||
| Ransomware | Eureka Casino Resort id5438 View details | Hospitality / Food & Beverage / Tourism | — | ||
|
Eureka Casinos was founded by the Lee family in Las Vegas, NV. It operates a wide-ranging number of businesses, including Eureka Casino Resort in Mesquite, NV. The Lee Family sold it to the employees in 2015 making it Nevada's first 100% employee owned casino |
|||||
| Ransomware | Tonga Communications id5396 View details | Tonga | Communication / Marketing | ||
|
Tonga Communications Corporation is a government-owned telecommunications provider offering mobile, fixed line, and internet services. It is based in Nuku'alofa. Tonga Communications Corporation Is Tonga's NO.1 cellular, fixedline & internet provider. |
|||||
| Ransomware | Diethelm Keller Aviation Pte Ltd id5392 View details | Singapore | Transportation / Travel / Logistics | ||
|
Diethelm Keller Aviation Pte Ltd (DKA), a global leader in galley inserts for the airline industry, is a wholly owned subsidiary of Diethelm Keller Brands Ltd. We are headquartered in Singapore. |
|||||
| Ransomware | Elektro Richter id5355 View details | Germany | Manufacturing / Engineering | — | |
|
Elektro Richter is a company that operates in the Electrical/Electronic Manufacturing industry. It employs 21-50 people and has $5M-$10M of revenue. The company is headquartered in Hildburghausen, Thuringia, Germany |
|||||
| Ransomware | Elim Clinic id5354 View details | South Africa | Healthcare / Pharma | — | |
|
Elim Clinic is a professional treatment centre that offers inpatient treatment to men and women, 18 years and older who suffer from substance use disorders and behaviour addiction. Elim has been in existence for more than six decades and has a wealth of experience |
|||||
| Ransomware | PFA Systems id5353 View details | Communication / Marketing | — | ||
|
PFA SYSTEMS, Inc. was started over thirty years ago with a single vision in mind, to provide reliable and safety conscientious service to our Suppliers and Drivers.This vision continues to carry on from day one when we were a single operator company, to our current fleet. We currently serve 14 states regionally and continuously work to establish trust between our clients and drivers.We specialize in Hazardous Bulk Liquid transport, but we are not limited to a single product. We integrate cutting edge safety practice and equipment to deliver the peace of mind our customers have come to rely upon and expect. |
|||||
| Ransomware | EnCom id5352 View details | Manufacturing / Engineering | — | ||
|
Founded in 2001, EnCom Inc is a specialty producer of custom compounded high-performance polymers serving the automotive, transportation, electronic, consumer goods, lawn and garden equipment, medical, material handling, and industrial industries. |
|||||
| Ransomware | European Window id5334 View details | Australia | Energy | — | |
|
European Window Company is an Australian leader in the design and installation of high efficiency thermal break windows, doors and sliding systems. |
|||||
| Ransomware | Bank of Africa id5318 View details | Senegal | Finance / Legal / Insurance | ||
|
Headquartered in the city of Dakar, Senegal, the story of Bank of Africa Group began in Mali in 1982, with the first Bank of Africa, which was created with almost no external help. Since 2010, the Bank of Africa Group has been majority-owned by BMCE Bank. |
|||||
| Ransomware | EightPixelsSquare id5289 View details | United Kingdom | Communication / Marketing | — | |
|
Founded in December 2012 and based in Derby, United Kingdom, EightPixelsSquare comprises of an elite team of 45 veteran game developers. Over 30 million players worldwide enjoy EightPixelsSquare's catalogue of games across iOS and Android platforms |
|||||
| Ransomware | Aglobis id5270 View details | Communication / Marketing | — | ||
|
Resistance shall not prevent us from fulfilling below mission: We connect industries for their sustainable operation and growth! Above services to be provided on a long term basis, i.e. indefinitely which is represented by the similar symbol in our logo Aglobis |
|||||
| Ransomware | Integerity Tax id5223 View details | Finance / Legal / Insurance | — | ||
|
Small business accounting, tax preparation, bookkeeping, payroll, individual taxes |
|||||
| Ransomware | Grace Church International id5224 View details | Communication / Marketing | — | ||
|
We Believe the Bible is God's supreme authority of the church and that prayer builds a relationship with God. We believe that faith empowers one to believe the impossible. That family is the foundation of the church and each person has a uniquely designed purpose |
|||||