Cisco Talos published IOCs ↗
- Evidence class
- provider reported
- Source family label
- MedusaLocker
- Source confidence
- Not reported
- Observed
- 2024-10-03 09:23 UTC
- Retrieved
- 2026-10-08 06:11 UTC
Ransomware galaxy based on https://docs.google.com/spreadsheets/d/1TWS238xacAto-fLKh1n5uTsdijWdCEsGIM0Y0Hvmc5g/pubhtml | Observed as recently as May 2022, MedusaLocker actors predominantly rely on vulnerabilities in Remote Desktop Protocol (RDP) to access victims’ networks. The MedusaLocker actors encrypt the victim's data and leave a ransom note with communication instructions in every folder con
2024/10/threat-actor-believed-to-be-spreading-new-medusalocker-variant-since-2022.jsonNetwork addresses are displayed in defanged form.
No file hashes or network indicators were published in this record.