AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
Æ / PUBLIC MALWARE INTELLIGENCE

Follow the evidence.

Published file metadata, source observations and research history in one connected catalog.

122,661Catalog records
55,566File records
137,028Source observations
123Family labels
Clear filters
2 MATCHING RECORDS
Export metadata JSON · CSV
REFERENCE1 SOURCE

MedusaLocker

MedusaLocker

Ransomware galaxy based on https://docs.google.com/spreadsheets/d/1TWS238xacAto-fLKh1n5uTsdijWdCEsGIM0Y0Hvmc5g/pubhtml | Observed as recently as May 2022, MedusaLocker actors predominantly rely on vulnerabilities in Remote Desktop Protocol (RDP) to access victims’ networks. The MedusaLocker actors encrypt the victim's data and leave a ransom note with communication instructions in every folder con

misp:galaxy-name="Ransomware"misp:galaxy-type="ransomware"misp-galaxy:ransomware="MedusaLocker"
First reported 2024-10-03 09:23 UTCOpen evidence record
REFERENCE1 SOURCE

MedusaLocker

MedusaLocker

Malware galaxy based on Malpedia archive. | A Windows ransomware that will run certain tasks to prepare the target system for the encryption of files. MedusaLocker avoids executable files, probably to avoid rendering the targeted system unusable for paying the ransom. It uses a combination of AES and RSA-2048, and reportedly appends extensions such as .encrypted, .bomber, .boroff, .breakingbad, .l

misp:galaxy-name="Malpedia"misp:galaxy-type="malpedia"misp-galaxy:malpedia="MedusaLocker"
First reported 2024-10-03 09:23 UTCOpen evidence record

Source labels and confidence are preserved. A filename or report mention alone does not establish that a file is malicious. Indicator observation dates describe the cited source; collection dates describe this catalog.