MedusaLocker is a Windows ransomware family first observed spreading in late September 2019, with victims identified worldwide. It is distinct from the similarly named Medusa ransomware operation.
Before encryption, MedusaLocker enables access to mapped network drives and restarts the Windows Workstation service to ensure network storage is accessible. It terminates processes associated with security products, databases, office applications, accounting software, web services, and VMware tools. It also deletes volume shadow copies and Windows system-state backups and disables Windows recovery features, reducing opportunities to restore affected systems without paying.
MedusaLocker enumerates files on local and mapped drives, encrypts them using AES, and protects the AES key with an embedded RSA-2048 public key. It excludes selected system directories and file types to preserve operating-system functionality and appends variant-specific extensions to encrypted files. After an encryption pass, it waits approximately one minute before scanning again for newly available files.
The ransomware maintains persistence by copying itself into the user's application-data area and creating a scheduled task that executes it every 30 minutes. It places ransom notes in directories containing encrypted files, instructing victims to contact the attackers for payment and decryption arrangements. The notes offer free decryption of one file as proof of recovery capability. The initial distribution mechanism for the early observed infections was not established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The vulnerability in ThrottleStop.sys has been assigned CVE-2025-7771. According to our information, the vendor is currently preparing a patch.
"A critical remote code execution (RCE) vulnerability, identified as CVE-2025-55182 and dubbed React2Shell, exists within the React Server Components (RSC) architecture, allowing unauthenticated attackers to execute arbitrary code..."
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Servifruit ... has fallen victim to a ransomware attack conducted by the group medusalocker.
"...web server exploitation campaigns in 2020 that primarily delivered MedusaLocker ransomware."
26 distinct techniques documented for this family, organized by ATT&CK tactic.
When installed, this ransomware will also copy itself to %UserProfile%\AppData\Roaming\svchostt.exe and create a scheduled task that launches the program every 30 minutes in order to remain resident.
MedusaLocker ransomware uses a batch file to execute PowerShell script invoke-ReflectivePEInjection [T1059.001].
When installed, this ransomware will also copy itself to %UserProfile%\AppData\Roaming\svchostt.exe and create a scheduled task that launches the program every 30 minutes in order to remain resident.
Erase VSS, disable FW using ransomware • Delete file using “sdelete.exe –p 5 <FileName>” • Delete eventlog using “pslog.exe -c security”
Удаляет теневые копии файлов... командами: vssadmin.exe Delete Shadows /All /Quiet wmic.exe SHADOWCOPY /nointeractive
MedusaLocker can also perform ICMP sweeping to identify other systems on the same network.
The malware uses ICMP sweeping to profile the network to identify other systems that can be used to maximize the likelihood of a ransom payment.
Стремится завершить следующие процессы, чтобы убедиться, что все файлы данных закрыты... sqlservr, sqlagent ... winword.exe ... java.exe
“Qualisteel ... has fallen victim to a ransomware attack conducted by the group medusalocker.”
It will then look for and terminate the following processes in order to shut down security programs and to make sure all data files are closed and accessible for encrypting
Finally, it clears the Shadow Volume Copies so that they cannot be used to restore files, removes backups made with Windows backup, and disables the Windows automatic startup repair using the following commands: vssadmin.exe Delete Shadows /All /Quiet ... wbadmin DELETE SYSTEMSTATEBACKUP
302 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
68 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware associated in this reference with an attack against Premiumfruits, involving the claimed extraction of 3,292 email addresses.
Ransomware identified as MedusaLocker was reported as responsible for an attack against Abv, a Bulgaria-based organization; 583 email addresses were reportedly extracted.
Ransomware family identified as responsible for the reported attack against Seznam; the report states that 115 email addresses were extracted.
Ransomware identified as responsible for the reported attack against Aokkef; the report states that 137 email addresses were extracted.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.