MedusaLocker is a Windows ransomware family first observed in late 2019 and operated as a ransomware-as-a-service model, with affiliates conducting intrusions and sharing ransom proceeds with developers. It is distinct from the separate Medusa ransomware operation and the Medusa Android banking trojan. MedusaLocker has affected organizations globally, including healthcare, education, government, finance, manufacturing, and technology environments. Operators commonly obtain access through exposed or weak Remote Desktop Protocol services, stolen remote-access credentials, phishing and spam campaigns, and exploitation of exposed VPN or edge-system vulnerabilities. Some campaigns have also used malicious attachments, exploit kits, deceptive downloads, malvertising, fake updates, and trojanized installers.
The malware encrypts Windows-hosted local data, mapped drives, accessible SMB shares, and other reachable network storage using AES encryption protected by embedded RSA public-key cryptography. Variants use multi-threaded and, in some cases, partial-encryption routines to accelerate impact. MedusaLocker enumerates network resources through ICMP and SMB and can remap drives, mount additional volumes, and target accessible shares, allowing one compromised system to affect broader enterprise storage. Later variants incorporated double-extortion pressure by threatening publication of stolen data.
MedusaLocker impairs recovery by deleting backups and shadow copies and disabling Windows recovery mechanisms. It terminates security, database, accounting, office, and virtualization-related processes to unlock files and reduce defensive visibility. It has used UAC-bypass methods, policy changes, safe-mode rebooting, and anti-debugging checks. Persistence is typically established through copies in the user profile and scheduled tasks or Windows Run-key execution. Encrypted directories receive ransom instructions directing victims to contact the operators for payment and decryption arrangements.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The vulnerability in ThrottleStop.sys has been assigned CVE-2025-7771. According to our information, the vendor is currently preparing a patch.
"A critical remote code execution (RCE) vulnerability, identified as CVE-2025-55182 and dubbed React2Shell, exists within the React Server Components (RSC) architecture, allowing unauthenticated attackers to execute arbitrary code..."
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Servifruit ... has fallen victim to a ransomware attack conducted by the group medusalocker.
"...web server exploitation campaigns in 2020 that primarily delivered MedusaLocker ransomware."
27 distinct techniques documented for this family, organized by ATT&CK tactic.
When installed, this ransomware will also copy itself to %UserProfile%\AppData\Roaming\svchostt.exe and create a scheduled task that launches the program every 30 minutes in order to remain resident.
MedusaLocker ransomware uses a batch file to execute PowerShell script invoke-ReflectivePEInjection [T1059.001].
When installed, this ransomware will also copy itself to %UserProfile%\AppData\Roaming\svchostt.exe and create a scheduled task that launches the program every 30 minutes in order to remain resident.
Erase VSS, disable FW using ransomware • Delete file using “sdelete.exe –p 5 <FileName>” • Delete eventlog using “pslog.exe -c security”
Удаляет теневые копии файлов... командами: vssadmin.exe Delete Shadows /All /Quiet wmic.exe SHADOWCOPY /nointeractive
MedusaLocker can also perform ICMP sweeping to identify other systems on the same network.
The malware uses ICMP sweeping to profile the network to identify other systems that can be used to maximize the likelihood of a ransom payment.
Стремится завершить следующие процессы, чтобы убедиться, что все файлы данных закрыты... sqlservr, sqlagent ... winword.exe ... java.exe
“Qualisteel ... has fallen victim to a ransomware attack conducted by the group medusalocker.”
It will then look for and terminate the following processes in order to shut down security programs and to make sure all data files are closed and accessible for encrypting
Finally, it clears the Shadow Volume Copies so that they cannot be used to restore files, removes backups made with Windows backup, and disables the Windows automatic startup repair using the following commands: vssadmin.exe Delete Shadows /All /Quiet ... wbadmin DELETE SYSTEMSTATEBACKUP
302 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
58 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware associated in this reference with an attack against Abourametals, a manufacturing-sector organization in the United Arab Emirates; the incident reportedly involved extraction of 25,448 email addresses.
A distinct ransomware family explicitly stated to be unrelated to Medusa ransomware.
Ransomware attributed in the report to the MedusaLocker group; the incident allegedly involved a breach of Licindia and extraction of nine email addresses.
Ransomware attributed in the report to the attack against Lawter, a U.S. manufacturing organization; the report states that 150 email addresses were extracted.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.