Cisco Talos published IOCs ↗
- Evidence class
- provider reported
- Source family label
- MedusaLocker
- Source confidence
- Not reported
- Observed
- 2024-10-03 09:23 UTC
- Retrieved
- 2026-10-08 06:11 UTC
Malware galaxy based on Malpedia archive. | A Windows ransomware that will run certain tasks to prepare the target system for the encryption of files. MedusaLocker avoids executable files, probably to avoid rendering the targeted system unusable for paying the ransom. It uses a combination of AES and RSA-2048, and reportedly appends extensions such as .encrypted, .bomber, .boroff, .breakingbad, .l
2024/10/threat-actor-believed-to-be-spreading-new-medusalocker-variant-since-2022.jsonNetwork addresses are displayed in defanged form.
No file hashes or network indicators were published in this record.