MedusaLocker is a Windows ransomware family associated with financially motivated extortion operations. It encrypts victim files and has been observed targeting local systems, mapped and shared network drives, and removable media, making it capable of impacting both standalone hosts and broader enterprise environments. The malware uses Windows cryptographic APIs and has been analyzed as employing symmetric file encryption with the resulting key protected by an embedded RSA public key. It commonly drops an HTML ransom note and repeatedly rescans infected systems for newly created files that remain unencrypted.
MedusaLocker includes multiple anti-recovery and defense-impairment behaviors. Observed variants delete shadow copies, remove restore points, disable startup repair, and attempt to terminate processes associated with security products and business applications. Some intrusions linked to MedusaLocker have also involved dedicated antivirus- and EDR-killing tooling, including bring-your-own-vulnerable-driver techniques used to disable endpoint protections before ransomware execution. Persistence has been observed through self-copying under deceptive system-like names and startup registration.
Intrusions associated with MedusaLocker have frequently been linked to opportunistic access methods, especially exposed or weakly protected RDP services, including brute-force activity and use of valid administrative credentials. Post-compromise activity has included credential theft with Mimikatz, lateral movement with administrative tooling such as PsExec and WMI-based execution, and network reconnaissance with scanning and share-enumeration utilities. Additional reporting has tied some MedusaLocker deployments to exploitation of internet-facing software and to HeartCrypt-packed payload chains in which a packed dropper is followed by an AV-killer component and then ransomware execution.
MedusaLocker has affected organizations across multiple countries and sectors, including public-sector entities, manufacturing, telecommunications, legal and business services. It is distinct from the separate Medusa ransomware operation and from other malware families using similar naming.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The vulnerability in ThrottleStop.sys has been assigned CVE-2025-7771. According to our information, the vendor is currently preparing a patch.
"A critical remote code execution (RCE) vulnerability, identified as CVE-2025-55182 and dubbed React2Shell, exists within the React Server Components (RSC) architecture, allowing unauthenticated attackers to execute arbitrary code..."
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"...web server exploitation campaigns in 2020 that primarily delivered MedusaLocker ransomware."
26 distinct techniques documented for this family, organized by ATT&CK tactic.
“MEDUSALOCKER… Persistence is established using a scheduled task.” and “Scheduled Task/Job (T1053) · Scheduled Task (T1053.005)”
“MEDUSALOCKER… Persistence is established using a scheduled task.” and “Scheduled Task/Job (T1053) · Scheduled Task (T1053.005)”
“MEDUSALOCKER… Persistence is established using a scheduled task.” and “Scheduled Task/Job (T1053) · Scheduled Task (T1053.005)”
“AVADDON, ThunderX and RANZY have different implementations to obfuscate both the RSA key and the strings.”
After the "Adding to Autoload" debug message it will rename itself to svchost.exe ... It also copies itself to %APPDATA% after renaming to executable to "svchostt.exe".
MedusaLocker will try to terminate the following processes by their name. The List contains Security Software as well as Services commonly used in productive environments such as SQL or Webservers.
Ransomware victim advisories tagged France total 213 items in the past 6 months.
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
39 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware used in attacks against French local government entities; in the cited case it was associated with data theft from a municipal administration and victim advisory postings.
Separate older ransomware family mentioned only to distinguish it from Medusa RaaS.
Ransomware identified in the report as responsible for the attack against Mairie Thiverval Grignon.
Ransomware identified as responsible for the attack against FunkeScheid.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.