Medusa is a financially motivated ransomware group that first emerged in June 2021 as a closed ransomware variant before transitioning to a Ransomware-as-a-Service (RaaS) model. While affiliates deploy the ransomware, core developers maintain centralized control over crucial operations such as ransom negotiations. The group is assessed with high confidence to be of Russian origin, indicated by its avoidance of targets within Russia and Commonwealth of Independent States (CIS) countries, its activity on Russian-language dark web forums, and the use of Russian slang by its operators. What distinguishes Medusa from many other groups is its aggressive use of public channels, including a public Telegram channel, Facebook profile, and X (formerly Twitter) account under the brand 'OSINT Without Borders,' to exert pressure on victims and enhance its reputation. Medusa also employs a notable triple extortion scheme, demanding an additional ransom even after initial payment, a tactic less common