AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← Catalog
REFERENCEPUBLIC INTELLIGENCE

MedusaLocker

Malware galaxy based on Malpedia archive. | A Windows ransomware that will run certain tasks to prepare the target system for the encryption of files. MedusaLocker avoids executable files, probably to avoid rendering the targeted system unusable for paying the ransom. It uses a combination of AES and RSA-2048, and reportedly appends extensions such as .encrypted, .bomber, .boroff, .breakingbad, .l

Reference details

Primary displayed family label
MedusaLocker
Source context
2024/10/threat-actor-believed-to-be-spreading-new-medusalocker-variant-since-2022.json
First reported
2024-10-03 09:23 UTC
Last reported
2024-10-03 09:23 UTC
Catalog updated
2026-10-08 06:11 UTC

Source family labels

MedusaLocker

Tags

misp:galaxy-name="Malpedia"misp:galaxy-type="malpedia"misp-galaxy:malpedia="MedusaLocker"

Published indicators

Network addresses are displayed in defanged form.

No file hashes or network indicators were published in this record.

Source observations

Cisco Talos published IOCs ↗

Evidence class
provider reported
Source family label
MedusaLocker
Source confidence
Not reported
Observed
2024-10-03 09:23 UTC
Retrieved
2026-10-08 06:11 UTC

Research references