MesudaLocker is a ransomware threat actor name associated in reporting with use of the ThrottleBlood endpoint security killing tool. Available high-confidence information in this context is limited: MesudaLocker is referenced through tooling overlap rather than a detailed campaign profile. ThrottleBlood has been linked to MesudaLocker and DragonForce attacks, indicating MesudaLocker has been associated with defense-evasion activity intended to disable or impair security products during ransomware intrusions. No additional corroborated details are available here regarding origin, victimology, geographic focus, operational structure, aliases beyond the canonical name, or whether MesudaLocker operates as a distinct group, brand, or affiliate cluster.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.