MedusaLocker has continued to evolve from its 2019 origins into a mature ransomware operation that targets enterprise networks through exposed or weakly secured RDP, stolen or brute-forced credentials, phishing, spam, and vulnerable VPN or edge devices. U.S. government reporting has described the threat as a ransomware-as-a-service model in which affiliates conduct intrusions and share proceeds with developers, while multiple technical profiles show the malware encrypting local disks, mapped drives, accessible SMB shares, and broader network resources after gaining a foothold. Later variants, including MedusaLocker v3 or BabyLockerKZ, also steal data to support double extortion and focus on maximizing damage inside victim environments rather than relying on external command-and-control traffic.
Across variants, MedusaLocker uses AES-256 encryption with RSA-2048 key protection, deletes shadow copies and backups to hinder recovery, and establishes persistence through scheduled tasks, roaming-profile executables, and registry-based mechanisms such as HKCU\SOFTWARE\PAIDMEMES or HKEY_CURRENT_USER\SOFTWARE\MDSLK\Self. Researchers and government agencies report additional behaviors including PowerShell execution, safe-mode reboots to impair defenses, UAC bypass, process termination to unlock files, ICMP network sweeping, CIDR-aware share discovery, hidden-volume mounting, and self-relaunch with a -network argument to widen encryption. The malware has used changing file extensions such as .meduza216 and varying ransom note names including How_to_back_files.html, HOW_TO_RECOVER_DATA, and related templates, with victims reported across healthcare, finance, government, and manufacturing.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
15 events from the most recent confirmed update back to the earliest known activity.
Howler Cell published an analysis of MedusaLocker v3, also called BabyLockerKZ, describing a newer variant with embedded XOR-decrypted configuration, registry-based persistence, subnet parsing, and expanded network encryption behavior.
Cyble reported that MedusaLocker had targeted 24 victims worldwide since January 2023, with the United States the most affected country and healthcare, education, and government among the targeted sectors. The report also analyzed a variant appending the .itlock4 extension and described its privilege escalation, persistence, backup deletion, and network/SMB enumeration behavior.
The FBI, CISA, the U.S. Department of the Treasury, and FinCEN issued a joint advisory describing MedusaLocker as a likely ransomware-as-a-service operation and detailing its tactics, techniques, and indicators of compromise.
The joint U.S. government advisory stated that MedusaLocker actors had been observed as recently as May 2022.
Cisco Talos published a threat spotlight on MedusaLocker describing its network-aware encryption behavior, persistence via scheduled tasks, shadow copy deletion, and released Snort SIDs 53662 through 53665 for detection.
BleepingComputer published an early technical write-up on MedusaLocker describing its persistence via svchostt.exe and a scheduled task, shadow copy and backup deletion, mapped-drive access, and AES-plus-RSA encryption. The report also documented multiple extensions including .encrypted, .bomber, .boroff, .breakingbad, .locker16, .newlock, .nlocker, and .skynet, along with ransom notes HOW_TO_RECOVER_DATA.html or Readme.html using the contact emails sambolero@tutanoa.com and rightcheck@cock.li.
A MedusaLocker variant from the 12 June 2020 timeframe used the .EG extension, demanded 1 BTC, and included the Bitcoin address 1BkmiGWPLum8MzusqZsq6Tn7v4oUjqPLjC.
A separate MedusaLocker variant documented on 25 December 2019 used the .ReadInstructions extension and added a message claiming the victim network had been penetrated and confidential data stolen.
A MedusaLocker variant documented on 25 December 2019 used the .READINSTRUCTIONS extension and dropped the ransom note RECOVER_INSTRUCTIONS.html.
Variants documented in November 2019 used the .ReadTheInstructions extension and the ransom note INSTRUCTIONS.html.
Variants documented in late October 2019 used the .decrypme extension and dropped the ransom note HOW_TO_OPEN_FILES.html.
A MedusaLocker variant documented on 22 October 2019 used the .encrypted extension and the contact emails crypt2020@outlook.com and cryptt2020@protonmail.com.
A cited MedusaLocker sample carried a file creation timestamp of 5 October 2019, providing an explicit anchor for early malware development or packaging.
MedusaLocker activity became notable in early October 2019 as the ransomware family began drawing broader attention from researchers.
The earliest MedusaLocker samples referenced in the sources were detected in late September 2019, marking the beginning of observed activity for the ransomware family.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
cyderes.com
Open sourceblog.cyble.com
Open sourcecisa.gov
Open sourceblog.talosintelligence.com
Open sourcebleepingcomputer.com
Open sourceid-ransomware.blogspot.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.