Medusa Group A.I CyberSecurity Scoring
Medusa Group
Company Information
Website:http://www.medusagroup.pl
Employees number:57
Number of followers:0
NAICS:54131
Industry Type:Architecture and Planning
Homepage:medusagroup.pl
Medusa Group Risk Score (AI oriented)
Between 700 and 749
Medusa GroupArchitecture and Planning
Updated:
11/06/2026
11/06/2026
749/1000
Moderate
Ba
Medusa Group Global Score (TPRM)
xxxx
Medusa GroupArchitecture and Planning
Score locked

Medusa GroupModerate
Current Score
749Ba (MODERATE)
01000
1 incidents
-68 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JULY 2026
751
JUNE 2026
749
MAY 2026
749
APRIL 2026
814
Ransomware
01 Apr 2026 • Medusa Group
The Gentlemen, Medusa and Cisco: The Gentlemen Ransomware Claims 478 Victims, Can Spread Like a Worm
The Gentlemen Ransomware Operation: A Rising Threat with AI and RaaS Roots
746
CRITICAL-68
MEDCISOPE1781209579
The Gentlemen Ransomware Operation: A Rising Threat with AI and RaaS Roots
A new analysis by PRODAFT has uncovered the evolution of The Gentlemen, a financially motivated ransomware group that began as an affiliate for established ransomware-as-a-service (RaaS) operations like LockBit, Qilin, and Medusa before launching its own independent program in July 2025. Tracked as Phantom Mantis, the group is led by a Russian-speaking cybercriminal known as LARVA-368 a 36-year-old identified as Alexander Andreevich Yapaev from Izhevsk, Russia, with aliases including hastalamuerte, ArmCorp, and santamuerte.
Since its inception, The Gentlemen has claimed 478 victims, with a surge in activity making it one of the most prolific ransomware actors, responsible for 10% of global ransomware incidents in April 2026. The group’s transition to independence followed a payment dispute with Qilin, where LARVA-368 accused the RaaS operator of an exit scam, allegedly defrauding affiliates of $48,000. PRODAFT noted that Phantom Mantis may have spread disinformation to recruit Qilin affiliates by discrediting the group.
The Gentlemen operates with a sophisticated infrastructure, leveraging AI for ransomware development, tool maintenance, and post-exploitation procedures. Its affiliate program offers a 90/10 profit split, attracting partners with aggressive incentives. Affiliates must provide at least 1GB of stolen victim data to access the panel, a tactic designed to block researchers and law enforcement. The group supports multiple ransomware variants, including Windows, Linux, ESXi, and LVM-targeting strains, and uses open-source messaging platforms like Tox and SimpleX Chat for communication.
Initial access is typically gained through vulnerable edge devices particularly Cisco and Fortinet FortiGate systems followed by Active Directory exploitation using tools like NetExec, RelayKing, and PrivHound. The ransomware employs a hybrid encryption scheme (X25519 key exchange with XChaCha20) and can self-propagate as a worm when executed with the `--spread` argument. Microsoft, tracking the group as Storm-2697, noted that the Go-based malware is obfuscated with Garble and can wipe recoverable artifacts when run with the `--wipe` flag.
The Gentlemen’s attacks exhibit a high degree of adaptability, with dwell times ranging from two to six weeks. The group targets VMware infrastructure and employs multi-channel extortion, combining ransomware with email and phone-based pressure tactics. A recent leak of the group’s internal Rocket.Chat database spanning November 2025 to April 2026 revealed a structured criminal enterprise with clear role divisions, exploiting vulnerabilities like CVE-2024-55591, CVE-2025-32433, and CVE-2025-33073. In March 2026, an exposed toolkit on a Russian bulletproof host further exposed the group’s full intrusion lifecycle, from reconnaissance to encryption.
Victim distribution is global, with only 13% in the U.S., while the majority are concentrated in Thailand, the U.K., Brazil, Germany, and India. The group’s rapid development cycle was demonstrated in April 2026 when it released a same-day patch after a decryptor was made public. With roots dating back to at least 2020 including prior affiliations with the Embargo ransomware group LARVA-368’s expertise has positioned The Gentlemen as a formidable and evolving threat in the cybercrime landscape.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MARCH 2026
814
FEBRUARY 2026
814
JANUARY 2026
814
DECEMBER 2025
814
NOVEMBER 2025
814
OCTOBER 2025
814
SEPTEMBER 2025
814
AUGUST 2025
814
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Medusa Group ??
What was Medusa Group's A.I Rankiteo Cyber Score in June 2026 ??
What was Medusa Group's A.I Rankiteo Cyber Score in May 2026 ??
What was Medusa Group's A.I Rankiteo Cyber Score in April 2026 ??
What was Medusa Group's A.I Rankiteo Cyber Score in March 2026 ??
What was Medusa Group's A.I Rankiteo Cyber Score in February 2026 ??
What was Medusa Group's A.I Rankiteo Cyber Score in January 2026 ??
What was Medusa Group's A.I Rankiteo Cyber Score in December 2025 ??
What was Medusa Group's A.I Rankiteo Cyber Score in November 2025 ??
What was Medusa Group's A.I Rankiteo Cyber Score in October 2025 ??
What was Medusa Group's A.I Rankiteo Cyber Score in September 2025 ??
What was Medusa Group's A.I Rankiteo Cyber Score in August 2025 ??
What is the average per-incident point impact on Medusa Group's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Medusa Group ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Medusa Group's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?