MedusaLocker is a Windows ransomware family active since September 2019 and assessed to operate as a ransomware-as-a-service operation, with affiliates conducting intrusions and sharing ransom proceeds with developers. It has targeted organizations globally, including healthcare, education, government, manufacturing, technology, and other enterprise sectors. MedusaLocker is distinct from the unrelated Medusa ransomware operation and Medusa Android banking trojan.
Operators commonly obtain access through exposed or vulnerable Remote Desktop Protocol deployments and also use phishing, spearphishing, and spam email campaigns. Following execution, MedusaLocker can elevate privileges through UAC-bypass techniques, establish scheduled-task persistence, terminate security and business application processes, and reboot systems into Safe Mode to impair defenses. It deletes shadow copies, backups, and recovery options to inhibit restoration.
The ransomware encrypts local storage, mapped drives, and accessible SMB shares using AES encryption with RSA-protected encryption keys. It can identify reachable systems through ICMP scanning, enumerate network shares, and encrypt accessible network resources, increasing impact across Windows enterprise environments. Variants use differing encrypted-file extensions and ransom-note formats, and commonly provide victim-specific negotiation instructions and an offer to decrypt a file as proof of capability.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The vulnerability in ThrottleStop.sys has been assigned CVE-2025-7771. According to our information, the vendor is currently preparing a patch.
"A critical remote code execution (RCE) vulnerability, identified as CVE-2025-55182 and dubbed React2Shell, exists within the React Server Components (RSC) architecture, allowing unauthenticated attackers to execute arbitrary code..."
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Servifruit ... has fallen victim to a ransomware attack conducted by the group medusalocker.
"...web server exploitation campaigns in 2020 that primarily delivered MedusaLocker ransomware."
27 distinct techniques documented for this family, organized by ATT&CK tactic.
When installed, this ransomware will also copy itself to %UserProfile%\AppData\Roaming\svchostt.exe and create a scheduled task that launches the program every 30 minutes in order to remain resident.
MedusaLocker ransomware uses a batch file to execute PowerShell script invoke-ReflectivePEInjection [T1059.001].
When installed, this ransomware will also copy itself to %UserProfile%\AppData\Roaming\svchostt.exe and create a scheduled task that launches the program every 30 minutes in order to remain resident.
Erase VSS, disable FW using ransomware • Delete file using “sdelete.exe –p 5 <FileName>” • Delete eventlog using “pslog.exe -c security”
Удаляет теневые копии файлов... командами: vssadmin.exe Delete Shadows /All /Quiet wmic.exe SHADOWCOPY /nointeractive
MedusaLocker can also perform ICMP sweeping to identify other systems on the same network.
The malware uses ICMP sweeping to profile the network to identify other systems that can be used to maximize the likelihood of a ransom payment.
Стремится завершить следующие процессы, чтобы убедиться, что все файлы данных закрыты... sqlservr, sqlagent ... winword.exe ... java.exe
“Qualisteel ... has fallen victim to a ransomware attack conducted by the group medusalocker.”
It will then look for and terminate the following processes in order to shut down security programs and to make sure all data files are closed and accessible for encrypting
Finally, it clears the Shadow Volume Copies so that they cannot be used to restore files, removes backups made with Windows backup, and disables the Windows automatic startup repair using the following commands: vssadmin.exe Delete Shadows /All /Quiet ... wbadmin DELETE SYSTEMSTATEBACKUP
302 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
61 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware identified as MedusaLocker was reported as responsible for an attack against Abv, a Bulgaria-based organization; 583 email addresses were reportedly extracted.
Ransomware family identified as responsible for the reported attack against Seznam; the report states that 115 email addresses were extracted.
Ransomware identified as responsible for the reported attack against Aokkef; the report states that 137 email addresses were extracted.
Ransomware associated in this reference with an attack against Abourametals, a manufacturing-sector organization in the United Arab Emirates; the incident reportedly involved extraction of 25,448 email addresses.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.