Skip to content

MedusaLocker

MedusaLocker is a Windows ransomware family associated with financially motivated extortion operations.

Profile source: Mallory opens in a new tab

MedusaLocker

Family profile

MedusaLocker is a Windows ransomware family associated with financially motivated extortion operations. It encrypts victim files and has been observed targeting local systems, mapped and shared network drives, and removable media, making it capable of impacting both standalone hosts and broader enterprise environments. The malware uses Windows cryptographic APIs and has been analyzed as employing symmetric file encryption with the resulting key protected by an embedded RSA public key. It commonly drops an HTML ransom note and repeatedly rescans infected systems for newly created files that remain unencrypted.

MedusaLocker includes multiple anti-recovery and defense-impairment behaviors. Observed variants delete shadow copies, remove restore points, disable startup repair, and attempt to terminate processes associated with security products and business applications. Some intrusions linked to MedusaLocker have also involved dedicated antivirus- and EDR-killing tooling, including bring-your-own-vulnerable-driver techniques used to disable endpoint protections before ransomware execution. Persistence has been observed through self-copying under deceptive system-like names and startup registration.

Intrusions associated with MedusaLocker have frequently been linked to opportunistic access methods, especially exposed or weakly protected RDP services, including brute-force activity and use of valid administrative credentials. Post-compromise activity has included credential theft with Mimikatz, lateral movement with administrative tooling such as PsExec and WMI-based execution, and network reconnaissance with scanning and share-enumeration utilities. Additional reporting has tied some MedusaLocker deployments to exploitation of internet-facing software and to HeartCrypt-packed payload chains in which a packed dropper is followed by an AV-killer component and then ransomware execution.

MedusaLocker has affected organizations across multiple countries and sectors, including public-sector entities, manufacturing, telecommunications, legal and business services. It is distinct from the separate Medusa ransomware operation and from other malware families using similar naming.

Capabilities

  • Brute Force
  • Byovd
  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Lateral Movement
  • Persistence
  • Privilege Escalation
  • Reconnaissance
  • Scanning

Operational record

20
Indicators
1
YARA rules
1
Ransom notes
5
Leak sites
1 available

Credential Theft

  • Invoke-TheHash
  • Mimikatz

Defense Evasion

  • HRSword
  • PCHunter
  • ProcessHacker

Discovery Enum

  • Advanced IP Scanner
  • Advanced Port Scanner
  • SoftPerfect NetScan

LOLBAS

  • PsExec

Offsec

  • Impacket

RMM Tools

  • Remote Desktop Plus (RDP+)

Published indicators

Sha256

19 total
  • dc4840a0992b218cbedd5a7ac5c711cb98f1f9e78a8ffdea37c694061dfd34c6
  • 48046fb0e566f5a2d184f84b76d6cadc458762556daed0ae4a3a1200afbefb54
  • c0c726a23111c220d022fcd01a85f9788249e42baece03f83b6059170453b801
  • 012657c4548d9c98223caa4cc7aa52fc083d6983d42fde16ca3271412e7fe3fe
  • 8edbb1944d94ff91ee917c31590b6d1d5690a52fc153e44355ee9749aa0f4625
  • 364f1b7466d8e4c9f55294ecf1f874c763bcf980c59b0250c613ac366def6aca
  • 5d5d639fdfbf632bb7d9f1bb28731217d09d36078ab5e594baf2a5a41267a5d2
  • 33a8024395c56fab4564b9baef1645e505e00b0b36bff6fad3aedb666022599a
  • b8c994e3ed7dcc9080916119ddc315533c129479f508676d7544b82b2e24745f
  • 63eb3d2886d9cb880c9b0d54b94f3e149b3b5b6215a33a0ef63588a09dcd4499

Tox

1 total
  • E9CD65687463F67F64937E961DD723DC82C79CB548375AAE8AA4A0698D356C5E7E157B22E8CD

Reported operators

Threat actors

1 named in public reporting
ANTHROPOID SPIDER

"...web server exploitation campaigns in 2020 that primarily delivered MedusaLocker ransomware."

Exploited software

Vulnerabilities linked to MedusaLocker

2 CVEs

MITRE ATT&CK

MedusaLocker in ATT&CK

27 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.