MedusaLocker
💰 eCrimeMotivation: financialLast active: 2026-09-23First seen: 2026-05-05
0
linked CVEs
Targeted industries
Agriculture and Food ProductionBusiness ServicesConstructionConsumer ServicesEducationHealthcareManufacturingNot FoundPublic SectorTelecommunicationTransportation/Logistics
Targeted regions
AEAUBRCACHCRDEFRGBILITMYUS
Observed as recently as May 2022, MedusaLocker actors predominantly rely on vulnerabilities in Remote Desktop Protocol (RDP) to access victims’ networks. The MedusaLocker actors encrypt the victim's data and leave a ransom note with communication instructions in every folder containing an encrypted file. The note directs victims to provide ransomware payments to a specific Bitcoin wallet address. MedusaLocker appears to operate as a Ransomware-as-a-Service (RaaS) model based on the observed split of ransom payments. Typical RaaS models involve the ransomware developer and various affiliates that deploy the ransomware on victim systems. MedusaLocker ransomware payments appear to be consistently split between the affiliate, who receives 55 to 60 percent of the ransom; and the developer, who receives the remainder.
Source: misp_galaxy · Collected: 2026-09-24
⚡ Vulnerabilities & Exploits0 CVEs
threat_actor_cve → cves / exploits.cve_ids
No CVE correlation on record for this actor yet.
🔍 Detection Coverage0 Sigma
Derived from linked CVEs — not a direct actor match
No Sigma rules mapped via this actor's CVEs yet.
🧬 YaraComing soon
🛰️ Infrastructure & IOCs0
No IOCs linked to this actor yet.
📰 Threat Intel Coverage2
Digest reports mentioning this actor (incl. aliases)
| Killing me gently: Inside Gentlemen’s EDR killer framework | matched as MedusaLocker | 2026-06-18 |
| EDR killers explained: Beyond the drivers | matched as MedusaLocker | 2026-03-19 |