Servifruit ... has fallen victim to a ransomware attack conducted by the group medusalocker.
MedusaLocker
MedusaLocker is a Windows ransomware family first identified in September 2019 that targets organizations worldwide.
MedusaLocker
Family profile
MedusaLocker is a Windows ransomware family first identified in September 2019 that targets organizations worldwide. It is deployed through affiliate-based ransomware operations, with attackers commonly obtaining access through vulnerable Remote Desktop Protocol configurations and through phishing or spam emails, including messages carrying ransomware payloads. MedusaLocker is unrelated to the similarly named Medusa ransomware operation and Medusa Android banking trojan.
The malware encrypts files on local disks, mapped network drives, and accessible SMB shares using AES, including AES-256 in documented variants, and protects the encryption keys with RSA-2048. It performs ICMP network discovery, identifies shared storage through SMB, and modifies Windows networking behavior to reconnect mapped drives and expand encryption coverage. It leaves ransom instructions in affected directories and periodically repeats encryption scans while excluding files necessary for system operation and files already encrypted.
MedusaLocker establishes persistence through scheduled tasks and a copy of its executable in the user's roaming profile. Documented execution chains use PowerShell-based reflective PE injection, and the family has used an ICMLuaUtil COM-based UAC bypass for privilege escalation. It terminates security, database, accounting, and other application processes, and can reboot systems into safe mode to evade security controls. To inhibit recovery, it deletes shadow copies and backups and disables Windows recovery features. Variants largely retain these core behaviors while changing encrypted-file extensions and ransom-note presentation.
Capabilities
- Defense Evasion
- Extortion
- Lateral Movement
- Persistence
- Privilege Escalation
- Process Injection
- Reconnaissance
- Scanning
Samples
Recent samples
1 sandbox sample in the Derp library, newest 1 shown
Reported operators
Threat actors
2 named in public reporting"...web server exploitation campaigns in 2020 that primarily delivered MedusaLocker ransomware."
Exploited software
Vulnerabilities linked to MedusaLocker
2 CVEsMITRE ATT&CK