MedusaLocker is a Windows ransomware family active since 2019 and commonly assessed as operating in a ransomware-as-a-service model. It has been used in intrusions worldwide and has affected organizations across sectors including healthcare, education, government, manufacturing, finance, technology, and small municipal entities. The family has evolved through multiple variants, including a v3 line also referred to as BabyLockerKZ, while retaining broadly consistent core behavior.
MedusaLocker commonly gains initial access through exposed or weakly secured Remote Desktop Protocol environments, brute-forced or stolen remote-access credentials, phishing and spam email campaigns, and exploitation of exposed VPN or edge-facing systems. After execution, it typically checks for elevated privileges and may use user account control bypass techniques to relaunch with administrative rights. It establishes persistence by copying itself into the roaming profile and creating scheduled tasks or run-key entries that repeatedly relaunch the payload.
The malware is network-aware and designed to maximize impact across enterprise environments. It enumerates local volumes, mapped network drives, SMB shares, and in some variants reachable hosts via ICMP. It can manipulate Windows settings to remap shared drives, relaunch itself for network-focused encryption, and encrypt data on accessible shared storage in addition to local disks. Some variants also mount hidden or unassigned volumes and parse subnet information to broaden encryption scope.
Before encryption, MedusaLocker impairs recovery and defenses by terminating processes and services associated with security products, databases, office applications, virtualization tools, and business software. It deletes shadow copies, removes backups, disables or alters Windows recovery behavior, and in some cases reboots systems into safe mode to reduce interference from security tooling. Anti-debugging and defense-evasion measures have also been observed.
MedusaLocker encrypts files using AES-256 and protects the symmetric key with an embedded RSA-2048 public key. Variants append differing encrypted-file extensions and drop ransom notes in affected directories, typically directing victims to contact the operators through email or Tor-based negotiation portals. Later activity has included double-extortion behavior, with operators claiming theft of confidential data and threatening publication if payment is not made.
The family has documented lineage links to Ako, MedusaReborn, ThunderX, and Ranzy Locker in some reporting. MedusaLocker is distinct from the separate Medusa ransomware operation.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The vulnerability in ThrottleStop.sys has been assigned CVE-2025-7771. According to our information, the vendor is currently preparing a patch.
"A critical remote code execution (RCE) vulnerability, identified as CVE-2025-55182 and dubbed React2Shell, exists within the React Server Components (RSC) architecture, allowing unauthenticated attackers to execute arbitrary code..."
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"...web server exploitation campaigns in 2020 that primarily delivered MedusaLocker ransomware."
27 distinct techniques documented for this family, organized by ATT&CK tactic.
When installed, this ransomware will also copy itself to %UserProfile%\AppData\Roaming\svchostt.exe and create a scheduled task that launches the program every 30 minutes in order to remain resident.
MedusaLocker ransomware uses a batch file to execute PowerShell script invoke-ReflectivePEInjection [T1059.001].
When installed, this ransomware will also copy itself to %UserProfile%\AppData\Roaming\svchostt.exe and create a scheduled task that launches the program every 30 minutes in order to remain resident.
Erase VSS, disable FW using ransomware • Delete file using “sdelete.exe –p 5 <FileName>” • Delete eventlog using “pslog.exe -c security”
Удаляет теневые копии файлов... командами: vssadmin.exe Delete Shadows /All /Quiet wmic.exe SHADOWCOPY /nointeractive
MedusaLocker can also perform ICMP sweeping to identify other systems on the same network.
The malware uses ICMP sweeping to profile the network to identify other systems that can be used to maximize the likelihood of a ransom payment.
Стремится завершить следующие процессы, чтобы убедиться, что все файлы данных закрыты... sqlservr, sqlagent ... winword.exe ... java.exe
Idex Group — an organization based in DE — has fallen victim to a ransomware attack conducted by the group medusalocker.
It will then look for and terminate the following processes in order to shut down security programs and to make sure all data files are closed and accessible for encrypting
Finally, it clears the Shadow Volume Copies so that they cannot be used to restore files, removes backups made with Windows backup, and disables the Windows automatic startup repair using the following commands: vssadmin.exe Delete Shadows /All /Quiet ... wbadmin DELETE SYSTEMSTATEBACKUP
302 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
52 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware identified as responsible for the attack against Idex Group, resulting in a data breach with 30 emails extracted.
Ransomware identified in the content as responsible for the attack against All Parts Dry Cleaning.
Ransomware identified as responsible for the attack against Twal Family IT Lab.
Ransomware used in attacks against French local government entities; in the cited case it was associated with data theft from a municipal administration and victim advisory postings.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.