Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Groups/G1051
MITRE ATT&CK Group

Medusa Group (G1051)

ShareXLinkedInRedditHN

[Medusa Group](https://attack.mitre.org/groups/G1051) has been active since at least 2021 and was initially operated as a closed ransomware group before evolving into a Ransomware-as-a-Service (RaaS) operation. Some reporting indicates that certain attacks may still be conducted directly by the ransomware’s core developers. Public sources have also referred to the group as “Spearwing” or “Medusa Actors.” (Citation: CISA Medusa Group Medusa Ransomware March 2025) (Citation: Broadcom Medusa Ransomware Medusa Group March 2025) [Medusa Group](https://attack.mitre.org/groups/G1051) employs living-off-the-land techniques, frequently leveraging publicly available tools and common remote management software to conduct operations. The group engages in double extortion tactics, exfiltrating data prior to encryption and threatening to publish stolen information if ransom demands are not met. (Citation: Security Scorecard Medusa Ransomware January 2024) For initial access, [Medusa Group](https://attack.mitre.org/groups/G1051) has exploited publicly known vulnerabilities, conducted phishing campaigns, and used credentials or access purchased from Initial Access Brokers (IABs). The group is opportunistic and has targeted a wide range of sectors globally. (Citation: Intel471 Medusa Ransomware May 2025)

▪Techniques used (57)

T1490Inhibit System RecoveryT1047Windows Management InstrumentationT1570Lateral Tool TransferT1543.003Windows ServiceT1489Service StopT1106Native APIT1583.006Web ServicesT1608.002Upload ToolT1027.010Command ObfuscationT1083File and Directory DiscoveryT1112Modify RegistryT1588.002ToolT1087.001Local AccountT1585.001Social Media AccountsT1567.002Exfiltration to Cloud StorageT1070.003Clear Command HistoryT1650Acquire AccessT1071.001Web ProtocolsT1686Disable or Modify System FirewallT1564.003Hidden WindowT1135Network Share DiscoveryT1090.003Multi-hop ProxyT1190Exploit Public-Facing ApplicationT1218.014MMCT1585.002Email AccountsT1078Valid AccountsT1105Ingress Tool TransferT1057Process DiscoveryT1559.001Component Object ModelT1219Remote Access ToolsT1003.003NTDST1018Remote System DiscoveryT1569.002Service ExecutionT1003.001LSASS MemoryT1573.002Asymmetric CryptographyT1486Data Encrypted for ImpactT1059.001PowerShellT1136.002Domain AccountT1657Financial TheftT1652Device Driver DiscoveryT1690Prevent Command History LoggingT1027.002Software PackingT1070.004File DeletionT1059.003Windows Command ShellT1069.002Domain GroupsT1553.002Code SigningT1505.003Web ShellT1529System Shutdown/RebootT1518.001Security Software DiscoveryT1016System Network Configuration DiscoveryT1685Disable or Modify ToolsT1046Network Service DiscoveryT1033System Owner/User DiscoveryT1082System Information DiscoveryT1021.001Remote Desktop ProtocolT1072Software Deployment ToolsT1548.002Bypass User Account Control

▪Software used (5)

S0160certutiltoolS1040RclonetoolS1244Medusa RansomwaremalwareS0002MimikatztoolS0029PsExectool
G1051on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.