Skip to content

MedusaLocker

MedusaLocker is a Windows ransomware family active since late 2019 and distinct from the Medusa ransomware operation.

Profile source: Mallory opens in a new tab

MedusaLocker

Family profile

MedusaLocker is a Windows ransomware family active since late 2019 and distinct from the Medusa ransomware operation. It is assessed to operate as a ransomware-as-a-service ecosystem, with affiliates conducting intrusions and sharing ransom proceeds with operators. MedusaLocker has affected organizations worldwide, including healthcare, education, government, finance, manufacturing, and technology sectors.

Operators commonly obtain access through exposed or weakly protected Remote Desktop Protocol services, compromised RDP or SMB credentials, vulnerable VPN and edge infrastructure, and phishing or spam email campaigns carrying malicious attachments or download links. The ransomware encrypts local volumes, mapped drives, accessible SMB shares, and other reachable network storage using AES encryption with RSA public-key protection. Variants may use partial, multithreaded encryption to increase speed and impact.

MedusaLocker performs network discovery through ICMP probing and SMB-share enumeration, enabling encryption across accessible network resources. It can terminate security, database, accounting, virtualization, and business-application processes to unlock files and reduce defenses. It also deletes shadow copies and backups, disables recovery features, and may restart systems in Safe Mode to impair endpoint protection. Persistence is commonly achieved through a copied executable and scheduled-task or Run-key execution. Some variants use UAC-bypass techniques to obtain elevated execution.

Later variants support double extortion: operators claim to steal confidential data before encryption and threaten public disclosure if payment is not made. Ransom notes direct victims to negotiate through attacker-controlled contact channels and may offer limited decryption as proof of recovery capability.

Capabilities

  • Brute Force
  • Defense Evasion
  • Exfiltration
  • Initial Access
  • Lateral Movement
  • Persistence
  • Privilege Escalation
  • Reconnaissance
  • Scanning

Operational record

20
Indicators
1
YARA rules
1
Ransom notes
5
Leak sites
0 available

Credential Theft

  • Invoke-TheHash
  • Mimikatz

Defense Evasion

  • HRSword
  • PCHunter
  • ProcessHacker

Discovery Enum

  • Advanced IP Scanner
  • Advanced Port Scanner
  • SoftPerfect NetScan

LOLBAS

  • PsExec

Offsec

  • Impacket

RMM Tools

  • Remote Desktop Plus (RDP+)

Published indicators

Sha256

19 total
  • dc4840a0992b218cbedd5a7ac5c711cb98f1f9e78a8ffdea37c694061dfd34c6
  • 48046fb0e566f5a2d184f84b76d6cadc458762556daed0ae4a3a1200afbefb54
  • c0c726a23111c220d022fcd01a85f9788249e42baece03f83b6059170453b801
  • 012657c4548d9c98223caa4cc7aa52fc083d6983d42fde16ca3271412e7fe3fe
  • 8edbb1944d94ff91ee917c31590b6d1d5690a52fc153e44355ee9749aa0f4625
  • 364f1b7466d8e4c9f55294ecf1f874c763bcf980c59b0250c613ac366def6aca
  • 5d5d639fdfbf632bb7d9f1bb28731217d09d36078ab5e594baf2a5a41267a5d2
  • 33a8024395c56fab4564b9baef1645e505e00b0b36bff6fad3aedb666022599a
  • b8c994e3ed7dcc9080916119ddc315533c129479f508676d7544b82b2e24745f
  • 63eb3d2886d9cb880c9b0d54b94f3e149b3b5b6215a33a0ef63588a09dcd4499

Tox

1 total
  • E9CD65687463F67F64937E961DD723DC82C79CB548375AAE8AA4A0698D356C5E7E157B22E8CD

Recent claims

Reported operators

Threat actors

2 named in public reporting
MedusaLocker

Servifruit ... has fallen victim to a ransomware attack conducted by the group medusalocker.

ANTHROPOID SPIDER

"...web server exploitation campaigns in 2020 that primarily delivered MedusaLocker ransomware."

Exploited software

Vulnerabilities linked to MedusaLocker

2 CVEs

MITRE ATT&CK

MedusaLocker in ATT&CK

48 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.