AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← Catalog
REFERENCEPUBLIC INTELLIGENCE

MedusaLocker

Ransomware galaxy based on https://docs.google.com/spreadsheets/d/1TWS238xacAto-fLKh1n5uTsdijWdCEsGIM0Y0Hvmc5g/pubhtml | Observed as recently as May 2022, MedusaLocker actors predominantly rely on vulnerabilities in Remote Desktop Protocol (RDP) to access victims’ networks. The MedusaLocker actors encrypt the victim's data and leave a ransom note with communication instructions in every folder con

Reference details

Primary displayed family label
MedusaLocker
Source context
2024/10/threat-actor-believed-to-be-spreading-new-medusalocker-variant-since-2022.json
First reported
2024-10-03 09:23 UTC
Last reported
2024-10-03 09:23 UTC
Catalog updated
2026-10-08 06:11 UTC

Source family labels

MedusaLocker

Tags

misp:galaxy-name="Ransomware"misp:galaxy-type="ransomware"misp-galaxy:ransomware="MedusaLocker"

Published indicators

Network addresses are displayed in defanged form.

No file hashes or network indicators were published in this record.

Source observations

Cisco Talos published IOCs ↗

Evidence class
provider reported
Source family label
MedusaLocker
Source confidence
Not reported
Observed
2024-10-03 09:23 UTC
Retrieved
2026-10-08 06:11 UTC

Research references