{"schema":"aeternae-malware-metadata/v1","generated_at":"2026-10-08T08:38:34+00:00","total_matching":2,"page":1,"page_size":200,"records":[{"id":"70e1a88e14d1fe9441342be6cf34ab5234112d1d5b0d2615c76983cdfbc6f586","kind":"reference","title":"MedusaLocker","family":"MedusaLocker","category":"Malware intelligence","summary":"Ransomware galaxy based on https://docs.google.com/spreadsheets/d/1TWS238xacAto-fLKh1n5uTsdijWdCEsGIM0Y0Hvmc5g/pubhtml | Observed as recently as May 2022, MedusaLocker actors predominantly rely on vulnerabilities in Remote Desktop Protocol (RDP) to access victims\u2019 networks. The MedusaLocker actors encrypt the victim's data and leave a ransom note with communication instructions in every folder con","first_seen":1727947385,"last_seen":1727947385,"created_at":1791439860,"updated_at":1791439860,"source_count":1,"data":{"context":"2024/10/threat-actor-believed-to-be-spreading-new-medusalocker-variant-since-2022.json","tags":["misp:galaxy-name=\"Ransomware\"","misp:galaxy-type=\"ransomware\"","misp-galaxy:ransomware=\"MedusaLocker\""],"aliases":[],"references":["https://github.com/Cisco-Talos/IOCs/blob/main/2024/10/threat-actor-believed-to-be-spreading-new-medusalocker-variant-since-2022.json"],"filenames":[],"features":[],"related_cves":[],"labels":["MedusaLocker"]},"observations":[{"source_id":"talos_ioc","source_url":"https://github.com/Cisco-Talos/IOCs/blob/main/2024/10/threat-actor-believed-to-be-spreading-new-medusalocker-variant-since-2022.json","source_label":"MedusaLocker","evidence_class":"provider_reported","confidence":null,"observed_at":1727947385,"fetched_at":1791439860,"data":{"context":"2024/10/threat-actor-believed-to-be-spreading-new-medusalocker-variant-since-2022.json","tags":["misp:galaxy-name=\"Ransomware\"","misp:galaxy-type=\"ransomware\"","misp-galaxy:ransomware=\"MedusaLocker\""],"aliases":[],"references":["https://github.com/Cisco-Talos/IOCs/blob/main/2024/10/threat-actor-believed-to-be-spreading-new-medusalocker-variant-since-2022.json"],"family":"MedusaLocker"}}],"indicators":[]},{"id":"bd567a5c9f5ff56a8dd85936053ad3b6debd361dfd70c8bb86e1a23e283c522c","kind":"reference","title":"MedusaLocker","family":"MedusaLocker","category":"Malware intelligence","summary":"Malware galaxy based on Malpedia archive. | A Windows ransomware that will run certain tasks to prepare the target system for the encryption of files. MedusaLocker avoids executable files, probably to avoid rendering the targeted system unusable for paying the ransom. It uses a combination of AES and RSA-2048, and reportedly appends extensions such as .encrypted, .bomber, .boroff, .breakingbad, .l","first_seen":1727947385,"last_seen":1727947385,"created_at":1791439860,"updated_at":1791439860,"source_count":1,"data":{"context":"2024/10/threat-actor-believed-to-be-spreading-new-medusalocker-variant-since-2022.json","tags":["misp:galaxy-name=\"Malpedia\"","misp:galaxy-type=\"malpedia\"","misp-galaxy:malpedia=\"MedusaLocker\""],"aliases":[],"references":["https://github.com/Cisco-Talos/IOCs/blob/main/2024/10/threat-actor-believed-to-be-spreading-new-medusalocker-variant-since-2022.json"],"filenames":[],"features":[],"related_cves":[],"labels":["MedusaLocker"]},"observations":[{"source_id":"talos_ioc","source_url":"https://github.com/Cisco-Talos/IOCs/blob/main/2024/10/threat-actor-believed-to-be-spreading-new-medusalocker-variant-since-2022.json","source_label":"MedusaLocker","evidence_class":"provider_reported","confidence":null,"observed_at":1727947385,"fetched_at":1791439860,"data":{"context":"2024/10/threat-actor-believed-to-be-spreading-new-medusalocker-variant-since-2022.json","tags":["misp:galaxy-name=\"Malpedia\"","misp:galaxy-type=\"malpedia\"","misp-galaxy:malpedia=\"MedusaLocker\""],"aliases":[],"references":["https://github.com/Cisco-Talos/IOCs/blob/main/2024/10/threat-actor-believed-to-be-spreading-new-medusalocker-variant-since-2022.json"],"family":"MedusaLocker"}}],"indicators":[]}]}