Credential Theft
- Invoke-TheHash
- Mimikatz
MedusaLocker is a Windows ransomware family associated with financially motivated extortion operations.
Profile source: Mallory opens in a new tabMedusaLocker
MedusaLocker is a Windows ransomware family associated with financially motivated extortion operations. It encrypts victim files and has been observed targeting local systems, mapped and shared network drives, and removable media, making it capable of impacting both standalone hosts and broader enterprise environments. The malware uses Windows cryptographic APIs and has been analyzed as employing symmetric file encryption with the resulting key protected by an embedded RSA public key. It commonly drops an HTML ransom note and repeatedly rescans infected systems for newly created files that remain unencrypted.
MedusaLocker includes multiple anti-recovery and defense-impairment behaviors. Observed variants delete shadow copies, remove restore points, disable startup repair, and attempt to terminate processes associated with security products and business applications. Some intrusions linked to MedusaLocker have also involved dedicated antivirus- and EDR-killing tooling, including bring-your-own-vulnerable-driver techniques used to disable endpoint protections before ransomware execution. Persistence has been observed through self-copying under deceptive system-like names and startup registration.
Intrusions associated with MedusaLocker have frequently been linked to opportunistic access methods, especially exposed or weakly protected RDP services, including brute-force activity and use of valid administrative credentials. Post-compromise activity has included credential theft with Mimikatz, lateral movement with administrative tooling such as PsExec and WMI-based execution, and network reconnaissance with scanning and share-enumeration utilities. Additional reporting has tied some MedusaLocker deployments to exploitation of internet-facing software and to HeartCrypt-packed payload chains in which a packed dropper is followed by an AV-killer component and then ransomware execution.
MedusaLocker has affected organizations across multiple countries and sectors, including public-sector entities, manufacturing, telecommunications, legal and business services. It is distinct from the separate Medusa ransomware operation and from other malware families using similar naming.
dc4840a0992b218cbedd5a7ac5c711cb98f1f9e78a8ffdea37c694061dfd34c648046fb0e566f5a2d184f84b76d6cadc458762556daed0ae4a3a1200afbefb54c0c726a23111c220d022fcd01a85f9788249e42baece03f83b6059170453b801012657c4548d9c98223caa4cc7aa52fc083d6983d42fde16ca3271412e7fe3fe8edbb1944d94ff91ee917c31590b6d1d5690a52fc153e44355ee9749aa0f4625364f1b7466d8e4c9f55294ecf1f874c763bcf980c59b0250c613ac366def6aca5d5d639fdfbf632bb7d9f1bb28731217d09d36078ab5e594baf2a5a41267a5d233a8024395c56fab4564b9baef1645e505e00b0b36bff6fad3aedb666022599ab8c994e3ed7dcc9080916119ddc315533c129479f508676d7544b82b2e24745f63eb3d2886d9cb880c9b0d54b94f3e149b3b5b6215a33a0ef63588a09dcd4499E9CD65687463F67F64937E961DD723DC82C79CB548375AAE8AA4A0698D356C5E7E157B22E8CDReported operators
"...web server exploitation campaigns in 2020 that primarily delivered MedusaLocker ransomware."
Exploited software
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.