Credential Theft
- Invoke-TheHash
- Mimikatz
MedusaLocker is a Windows ransomware family active since late 2019 and distinct from the Medusa ransomware operation.
Profile source: Mallory opens in a new tabMedusaLocker
MedusaLocker is a Windows ransomware family active since late 2019 and distinct from the Medusa ransomware operation. It is assessed to operate as a ransomware-as-a-service ecosystem, with affiliates conducting intrusions and sharing ransom proceeds with operators. MedusaLocker has affected organizations worldwide, including healthcare, education, government, finance, manufacturing, and technology sectors.
Operators commonly obtain access through exposed or weakly protected Remote Desktop Protocol services, compromised RDP or SMB credentials, vulnerable VPN and edge infrastructure, and phishing or spam email campaigns carrying malicious attachments or download links. The ransomware encrypts local volumes, mapped drives, accessible SMB shares, and other reachable network storage using AES encryption with RSA public-key protection. Variants may use partial, multithreaded encryption to increase speed and impact.
MedusaLocker performs network discovery through ICMP probing and SMB-share enumeration, enabling encryption across accessible network resources. It can terminate security, database, accounting, virtualization, and business-application processes to unlock files and reduce defenses. It also deletes shadow copies and backups, disables recovery features, and may restart systems in Safe Mode to impair endpoint protection. Persistence is commonly achieved through a copied executable and scheduled-task or Run-key execution. Some variants use UAC-bypass techniques to obtain elevated execution.
Later variants support double extortion: operators claim to steal confidential data before encryption and threaten public disclosure if payment is not made. Ransom notes direct victims to negotiate through attacker-controlled contact channels and may offer limited decryption as proof of recovery capability.
dc4840a0992b218cbedd5a7ac5c711cb98f1f9e78a8ffdea37c694061dfd34c648046fb0e566f5a2d184f84b76d6cadc458762556daed0ae4a3a1200afbefb54c0c726a23111c220d022fcd01a85f9788249e42baece03f83b6059170453b801012657c4548d9c98223caa4cc7aa52fc083d6983d42fde16ca3271412e7fe3fe8edbb1944d94ff91ee917c31590b6d1d5690a52fc153e44355ee9749aa0f4625364f1b7466d8e4c9f55294ecf1f874c763bcf980c59b0250c613ac366def6aca5d5d639fdfbf632bb7d9f1bb28731217d09d36078ab5e594baf2a5a41267a5d233a8024395c56fab4564b9baef1645e505e00b0b36bff6fad3aedb666022599ab8c994e3ed7dcc9080916119ddc315533c129479f508676d7544b82b2e24745f63eb3d2886d9cb880c9b0d54b94f3e149b3b5b6215a33a0ef63588a09dcd4499E9CD65687463F67F64937E961DD723DC82C79CB548375AAE8AA4A0698D356C5E7E157B22E8CDReported operators
Servifruit ... has fallen victim to a ransomware attack conducted by the group medusalocker.
"...web server exploitation campaigns in 2020 that primarily delivered MedusaLocker ransomware."
Exploited software
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.