Deep Dive on Medusa Ransomware Group

We’re still seeing Medusa actively targeting CNI, education, legal, insurance and manufacturing sectors in early 2025. As such we did a bit of a deep dive to learn more about them. Plenty of IOCs and TTPs in here if you’re a detection engineer in one of the targeted sectors!