MedusaLocker is a ransomware operation associated with attacks against organizations across multiple sectors and countries. Reported victims include organizations in manufacturing, technology, agriculture and food production, government, energy and utilities, healthcare, hospitality, and retail. The operation has been associated with a ransomware leak site and with claims of data extraction from victim environments, including business email-address data. Reported activity has affected organizations in North America, Europe, Asia, the Middle East, Australia, and southern Africa. Available reporting does not establish a reliable geographic origin, initial-access methods, malware execution details, encryption behavior in individual incidents, or a consistent set of post-compromise techniques. It is also referred to as medusa_locker, medusalocker_actors, and medusalocker_ransomware_actors.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
54 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
103 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Allegedly conducted a ransomware attack against Premiumfruits, a Spanish agriculture and food-production organization, resulting in the reported extraction of 3,292 email addresses.
Reported ransomware and data-extortion activity targeting Junta de Andalucía, a Spanish government organization.
Reported ransomware attack and alleged data theft targeting ATCO Ltd, a Canadian energy and utilities organization.
Ransomware activity targeting Abv in Bulgaria, with an alleged data theft involving 583 email addresses.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.