🌐Medusa
🌐 Medusa is a tracked threat actor in the Clankerusecase corpus. Attributed to ??. Primary motivation: Criminal. We map 14 detection use cases to this actor across 35 MITRE ATT&CK techniques, with 2 threat-intel articles citing them. Active in our corpus from 2026-02-12 to 2026-03-19.
crit 2
14Use cases
2Articles
35Techniques
0IOCs
Known aliases
Medusa ransomwareMedusaLocker
Top techniques
All other tracked techniques
T1003 · OS Credential DumpingT1003.001 · LSASS MemoryT1014 · RootkitT1021.002 · SMB/Windows Admin SharesT1027 · Obfuscated Files or InformationT1027.002 · Software PackingT1027.005 · Indicator Removal from ToolsT1027.009 · Embedded PayloadsT1037.001 · Logon Script (Windows)T1055 · Process InjectionT1059.001 · PowerShellT1059.003 · Windows Command ShellT1059.005 · Visual BasicT1068 · Exploitation for Privilege EscalationT1070.004 · File DeletionT1140 · Deobfuscate/Decode Files or InformationT1195.002 · Compromise Software Supply ChainT1204.001 · Malicious LinkT1204.004 · Malicious Copy and PasteT1218 · System Binary Proxy ExecutionT1219 · Remote Access ToolsT1489 · Service StopT1490 · Inhibit System RecoveryT1543.003 · Windows ServiceT1562.001 · T1562.001T1562.004 · T1562.004T1562.006 · T1562.006T1562.009 · T1562.009T1566 · PhishingT1566.001 · Spearphishing AttachmentT1566.002 · Spearphishing LinkT1569.002 · Service Execution
Detection use cases (14)
Medusa ransomware BYOVD driver drop (smol.sys/smuol.sys) chained with Defender tampering Medusa pre-encryption cascade: bcdedit/vssadmin recovery sabotage + .medusa or !!!READ_ME_MEDUSA!!! drop BYOVD: Genshin Impact mhyprot.sys driver dropped/loaded outside legitimate game install (Embargo evil-mhyprot-cli) EDRSilencer-style WFP filter blocking outbound traffic from named EDR binaries EDR-Freeze: WerFaultSecure.exe abused to suspend AV/EDR processes via MiniDumpWriteDump race Phishing-link click correlated to endpoint execution Email attachment opened from external sender Office app spawning script/LOLBin child process Fake CAPTCHA / clipboard-injected PowerShell (ClickFix / FakeCaptcha) PowerShell encoded / obfuscated command Ransomware-style mass file rename / extension change LSASS process access / dump (credential theft) Remote service execution — PsExec / SMB lateral movement Article-specific behavioural hunt — EDR killers explained: Beyond the driversThreat-intel articles (2)
crit EDR killers explained: Beyond the drivers · 2026-03-19