The hackers behind the Medusa ransomware claim to have at least 400 victimssince they began operating in January 2023. In fact, attacks appear to have increased by 42% between 2023 and 2024.

In the first two months of 2025, the group has claimed responsibility for more than 40 attacks, according to new data from Symantec. The cybersecurity firm is tracking the hacking group known as Spearwing.
“ Like the majority of ransomware operators, Spearwing and its affiliates carry out double-extortion attacks, stealing victims’ data and encrypting networks in order to increase pressure on victims to pay ransom ,” Symantec noted . “ If victims refuse to pay, the group threatens to publish the stolen data on their data leak website . ”
See also: Toronto Zoo: New details about last year's ransomware attack
The ransomware landscape continues to evolve, with new RaaS operations emerging all the time: Anubis, CipherLocker, Core, Dange, LCRYX, Loches, Vgod, and Xelera.
The hackers behind Medusa ransomware typically demand ransoms ranging from $100,000 to $15 million. They often target healthcare providers and non-profit organizations, financial providers, and government agencies.
Hackers often launch their attacks by exploiting known security vulnerabilities in popular applications. The Medusa ransomware gang may also use initial access brokers to compromise networks.
Once access is gained, hackers use remote management and monitoring (RMM) software such as SimpleHelp, AnyDesk or MeshAgent to gain permanent access. They also use the Bring Your Own Vulnerable Driver (BYOVD) technique to terminate antivirus processes (via KillAV). It is worth noting that KillAV has also been used in the past in BlackCat ransomware attacks.
See also: BianLian ransomware: Fake ransom notes sent to company CEOs
“The use of legitimate RMM software, PDQ Deploy, is another hallmark of Medusa ransomware attacks,” Symantec said. “It is commonly used by attackers to install other tools and files and move into victims’ networks.”
Some of the other tools deployed during these attacks include Navicat for accessing and executing database queries, RoboCopy , and Rclone for data extraction.
“Like most targeted ransomware groups, Spearwing tends to attack large organizations across a variety of sectors,” Symantec said. The group appears to have a purely financial motive.

Ransomware protection
One of the most effective strategies is to educate staff about cyberattacks. This can include learning the basics of cybersecurity, understanding the most common attack techniques, and learning best practices for protecting personal and corporate data. For example, it is essential to use strong and unique passwords and enable MFA on accounts wherever and whenever possible.
Additionally, the use of advanced security solutions, such as intrusion protection systems (IPS), intrusion detection systems (IDS), and antivirus software, can provide significant protection against cyberattacks. These tools can detect and repel attacks before they cause significant damage.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Network segmentation can also help protect organizations by preventing a potential attack from spreading to all systems.
See also: BackConnect malware links Black Basta and Cactus ransomware
Implementing a least privilege policy, which limits access to systems and applications to only those who truly need that access, can reduce the risk of ransomware attacks.
Updating all software and applications is also essential, as it fixes potential security vulnerabilities that hackers can exploit.
Finally, regularly backing up important data and implementing disaster recovery plans can ensure that, even if a cyberattack occurs, data can be recovered.
Source: thehackernews.com
