MedusaLocker is a financially motivated ransomware operation associated with the MedusaLocker ransomware family. It is also referred to as Medusa Locker and medusa_locker, with tracking labels including medusalocker_actors and medusalocker_ransomware_actors. It is distinct from the Medusa ransomware group; the two operations should not be conflated. MedusaLocker targets organizations across multiple countries and sectors, including manufacturing, transportation, information technology, healthcare, government, agriculture and food production, hospitality, energy, and utilities. Its reported targets span Europe, Africa, Asia, the Middle East, and the Americas, including organizations in France, Spain, Switzerland, Bulgaria, the Czech Republic, South Africa, India, China, the United Arab Emirates, Brazil, and Canada. The operation conducts ransomware attacks and uses dedicated leak sites to publicize victims, including healthcare organizations. Its activity includes exploitation of previously disclosed software vulnerabilities. Its country of origin and operator identities are not established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
53 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
103 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Reportedly conducted a ransomware attack against Rueegseggerag, a Switzerland-based organization using the domain rueegseggerag.ch. The report lists both the breach and discovery time as October 5, 2026, at 11:07 UTC, but provides no technical evidence or attack-chain details.
Identified as the group responsible for a ransomware attack against Millensys, a technology-sector organization in Brazil. The report lists both the breach and discovery date as October 5, 2026, and reports two extracted email addresses.
A post attributed to MedusaLocker lists Millensys (millensys.com), described as a Brazilian IT organization, and claims two emails were extracted. The victim was discovered on the leak site on October 5, 2026; no ransom demand, deadline, or supporting data samples are provided.
A post attributed to MedusaLocker lists Rueegseggerag, a Swiss manufacturing/engineering organization associated with rueegseggerag.ch, as a victim discovered on October 5, 2026. The listing notes one extracted email but provides no substantiating breach evidence, stolen-data size, ransom demand, or deadline.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.