MedusaLocker
Aliases: AKO Doxware, AKO Ransomware, MedusaReborn
- Malware type
- ransomware
- Family
- Malware family
- Last IoC activity
- 2026-07-19 16:23:29
- Profile updated
- 2026-07-07 12:47:18
Targeted industries: financial-services healthcare-and-pharmaceutical government-and-public-sector retail-and-hospitality transportation-and-logistics
Context
Observed as recently as May 2022, MedusaLocker actors predominantly rely on vulnerabilities in Remote Desktop Protocol (RDP) to access victims’ networks. The MedusaLocker actors encrypt the victim's data and leave a ransom note with communication instructions in every folder containing an encrypted file. The note directs victims to provide ransomware payments to a specific Bitcoin wallet address. MedusaLocker appears to operate as a Ransomware-as-a-Service (RaaS) model based on the observed split of ransom payments. Typical RaaS models involve the ransomware developer and various affiliates that deploy the ransomware on victim systems. MedusaLocker ransomware payments appear to be consistently split between the affiliate, who receives 55 to 60 percent of the ransom; and the developer, who receives the remainder.
Detection coverage
- 4 YARA rules
Detection rules
- ARKBIRD_SOLG_RAN_Medusalocker_July_2021_1 (yara-rule)
- ARKBIRD_SOLG_RAN_Medusalocker_Aug_2021_1 (yara-rule)
- DITEKSHEN_MALWARE_Win_Medusalocker (yara-rule)
- MALPEDIA_Win_Medusalocker_Auto (yara-rule)
Reports & references
- CrowdStrike — Double Trouble Ransomware Data Leak Extortion Part 1 (report)
- CrowdStrike — Report2021Gtr (report)
- CrowdStrike — Double Trouble Ransomware Data Leak Extortion Part 2 (report)
- docs.google.com — 1Mi8Z2Tbhmqq5X8Wf Ozv3Dvjz5Sjos 3 (report)
- jsac.jpcert.or.jp — Jsac2020 1 Tamada Yamazaki Nakatsuru En (report)
- ke-la.com — How Ransomware Gangs Find New Monetization Schemes And Evolve In Marketing (report)
- CISA — Aa20 345A (report)
- blackberry.com — Wp Spark State Of Ransomware (report)
- Microsoft — Ransomware Groups Continue To Target Healthcare Critical Services Heres How To Reduce Risk (report)
- medium.com — Inside View Of Brazzzersff Infrastructure 89B9188Fd145 (report)
- Mandiant — Chasing Avaddon Ransomware (report)
- CISA — Aa22 181A (report)
- CISA — Aa22 181A Stopransomware Medusalocker (report)
- asec.ahnlab.com — 48940 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Medusalocker (report)
- cloudsek.com — Technical Analysis Of Medusalocker Ransomware (report)
- theta.co.nz — Part 2 Analysing Medusalocker Ransomware (report)
- theta.co.nz — Part 3 Analysing Medusalocker Ransomware (report)
- dissectingmalwa.re — Try Not To Stare Medusalocker At A Glance (report)
- carbonblack.com — Tau Threat Analyis Medusa Locker Ransomware (report)
- medium.com — Decrypting The Mystery Of Medusalocker 7128795Cf9F0 (report)
- Cisco Talos — Medusalocker (report)
- twitter.com — 1215194488714346496 (report)
- theta.co.nz — Part 1 Analysing Medusalocker Ransomware (report)
- id-ransomware.blogspot.com — Medusalocker Ransomware (report)