logo

'Spearwing' RaaS Group Ruffles Feathers in Cyber Threat Scene

ID: 8ac23dcc-2e94-594b-87fc-01614fb47b2b

STIX ID: report--8ac23dcc-2e94-594b-87fc-01614fb47b2b

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2025-03-07

Date Updated: 2026-04-21

Author: Kristina Beek, Associate Editor, Dark Reading

...
...

Medusa ransomware, attributed to a group known as "Spearwing," has been used in double-extortion campaigns since 2023 with nearly 400 victims listed on its leak site; ransom demands range from $100,000 to $15 million. The group exploits unpatched public-facing services (notably Microsoft Exchange), leverages remote management and admin tools for lateral movement, appends a .medusa extension and drops a "!READ_ME_MEDUSA!!!.txt" ransom note, and may operate either as a tightly controlled RaaS or a single cohesive operator with consistent TTPs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.