Ransomware Intelligence

medusalocker

Ransomware group profile

39Victims
RussiaSource country
111Impact score
Also Known As
Spearwing

Description

Medusa is a ransomware group known for its targeted attacks on various sectors, particularly healthcare and finance. Utilizing advanced encryption and double extortion tactics, they demand ransoms while threatening to release stolen data. Medusa is distinctive for their public pressure tactics and employing affiliates to conduct their operations.

Key insights

  • Medusa employs sophisticated techniques including advanced encryption algorithms and obfuscation methods.
  • They primarily target healthcare and financial sectors but have also begun exploiting supply chains through compromised managed service providers.
  • The group utilizes double extortion methods, encrypting data and threatening to release sensitive information if the ransom is not paid.
  • Medusa has been linked to other ransomware groups and operates on a ransomware-as-a-service model.
  • Their initial access often comes from phishing campaigns, exploiting software vulnerabilities, and unsecured RDP connections.
  • Medusa has a notable presence on public channels to pressure victims, under aliases associated with their operations.

Threat Level & Status Breakdown

For medusalocker · Based on incidents in selected period

2.1threat level
Aggressiveness5/ 10
Lethality0/ 10
Criticality1.3/ 10

Status Breakdown

Claimed100.0%39
First seenSep 2025
Last seenJun 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedJun 18, 2026

Recent activity

Monthly attack count for medusalocker in the selected period

39Total attacks
35peak in May
9.8avg / month
SepNovMayJun09182736

Intelligence

IOCs, YARA/Sigma rules, and related families for medusalocker

  1. ac7741bca86793d28659b358f734a65e
  2. 917e115cc403e29b4388e0d175cbfac3e7e40ca1742299fbdb353847db2de7c2
  3. 8e846ed965bbc0270a6f58c5818e039ef2fb78def4d2bf82348ca786ea0cea4f
  4. 50520639cf77df0c15cc95076fac901e3d04b708
  5. f0ac3999d4020cd051052a0627a2056d
  6. 84828f31d741f92ce4bca98cfc2148ff8cff6663e2908a025b1386dd4953ffef
  7. 86d92fc3ba2b3536893b8e753da9cbae70063a50
  8. 632be2363c7a13be6d5ce0dca11e387bd0a072cc962b004f0dcf3c1f78982a5a
  9. 9c1a0a6ebf3184a621cd5509f937cdd1c04c52316bc94eaaf8328b4873b303f0
  10. a57f84e3848ab36fd59c94d32284a41e
  11. 5ff8acd652cc134b84213865aa3f74667c09a331cfa9affd2a2668ce78751516
  12. 468121e7d6952799f92940677268937c4c5f92ed
  13. 841ec2dec944964fc54786a1167713ff
  14. 721af117726af1385c08cc6f49a801f3cf3f057d9fd26fcec2749455567888e7
  15. 296d28eb7b66aa2cbea7d9c2e7dc1ad6ce6f97d44d34139760c38817aec083e7
  16. bfc17da86d6ae78228a232244157449eee1a6644
  17. 3037049411db0453c91e60393a248be2
  18. 65233da43bb5dfc9e0a7db7576c064f37efa6effcaf48fc60f7ab339f9ce03f9
  19. c53c93a445d751387eb167e5a2b901da
  20. 816013f665dc689fa9ad81762638d5ed3b7e9ccd
  21. 3a8a60416b7b0e1aa5d17eefb0a45a16
  22. 270c3354b3ee2940b499e365eaba143fba9d458f434dc38e663dc0f08e96121e
  23. 9b04a93e05ccff94667f04bffa7af600
  24. eeb830e36bc2ecc226ee8d13e37c1a39
  25. 77daf77d9d2a08cc22981c004689b870f74544b5
  26. 374ef83de2b254c4970b830bb93a1dd79955945d24b824a0b35636e14355fe05
  27. 8de54cad9d6316679580c91117b484acb493ab72
  28. b7703a59c39a0d2f7ef6422945aaeaaf061431af0533557246397551b8eed505
  29. f800e95135a980cc5762da3cbc13b566
  30. d9390bbbc6e399a388ac6ed601db4406eeb708f3893a40f88346ee002398955c
  31. 827d8ae502e3a4d56e6c3a238ba855a7
  32. 1cc2d1f2a991c19b7e633a92b1629641c019cdeb
  33. 1b7aee68f384e252286559abc32e6dd1
  34. 4e152dacab201c5bf5c22c93e31e9475
  35. f9c6dca22e336cf71ce4be540905b34b5a63a7d02eb9bbd8a40fc83e37154c22
  36. 8a4928ac9089adc4a153741d2f1c784a
  37. a53a9ca8a074c7108f8412c3f8c1fc5d
  38. 330ddac1f605ff8abf60880c584ed797
  39. 466dafa82a4460dcad722d2ad9b8ca332e9a896fc59f06e16ebe981ad3838a6b
  40. 74c2a7527b5ae4efb20631867d871ceb28a56c8bd5bd545739c3bbbc1755414f
  41. e57ba1a4e323094ca9d747bfb3304bd12f3ea3be5e2ee785a3e656c3ab1e8086
  42. 453257c3494addafb39cb6815862403e827947a1e7737eb8168cd10522465deb
  43. 651846e962ea48d797af4c81828f2badee5efc14e10ac75b003f90da82ad64f8
  44. eb67db00facad9154b98292b91908f051befdab6d7dd6b08f408f763af4c805b
  45. 77962a384d251f0aa8e3008a88f206d6cb1f7401c759c4614e3bfe865e3e985c
  46. 2173b43a66070aadf052ab66dd6933ce
  47. 0e43a0f747a60855209b311d727a20bf
  48. 2716c60c28cf7f7568f55ac33313468b
  49. 050dbd816c222d3c012ba9f2b1308db8e160e7d891f231272f1eacf19d0a0a06
  50. 599232eb867312bc9659c702ef607abfd3a65d18c61a06dfcec803c8744f9fea
  51. 6b05a1e9faf5b77bad1826bacf322b24
  52. 107d1f6cab03e59229ca6951cc1fa29b3900115a2805a5a599b24cc48e7ba7af
  53. a97a28276e4f88134561d938f60db495
  54. 62bed88bd426f91ddbbbcfcd8508ed6a
  55. 02a0ea73ccc55c0236aa1b4ab590f11787e3586e
  56. cb1280f6e63e4908d52b5bee6f65ec63
  57. 4a9dde3979c2343c024c6eeeddff7639be301826dd637c006074e04a1e4e9fe7
  58. ed241c92f9bc969a160da2c4c0b006581fa54f9615646dd46467d24fe5526c7a
  59. bcd952d2995d187c5a87ec0e03b638e02d7157b9a01d4e7c28ce7a6d6b28ac42
  60. 54de95cc33834a2f877ba4842860af27
  61. ac0dce3b0f5b8d187a2e3f29efc358538fd4aa45
  62. 76000c77ea9a214f5b2ae8cc387809db
  63. 91416e90b03e799bcbde19adac80e846639716e138ea7fd3504772ad2c21f371
  64. b441d262de2c5355bfd64d984342d767
  65. 328d0bb0792bfb4bb92204d21ae2dc7fe1ef61d0
  66. 9e82ee5bde6b5d29281a3c280e6d1f2e
  67. 80e8defa5377018b093b5b90de0f2957f7062144c83a09a56bba1fe4eda932ce
  68. 4a869e4a816476f12d5cd6aab0625c5f6aab97714a486f6b8a5f484cbc8981f6
  69. 9ea86dccd5bbde47f8641b62a1eeff07
  70. ba44c22a3224c3a201202b69d86df2a78f0cd1d4ac1119eb29cae33f09027a9a
  71. 4bace6e0b61f5169bb0ca7f48c38aea2
  72. 91025d6f02e542f2e37ffce7d0ce8b51
  73. b4f9e77ce3bc44b5418d82f645cdcb4cf149e6d9204bb876c30f7038498759af
  74. d58e06727c551756cbee1fc6539929553a09878b
  75. 3c7480998ade344b74e956f7d3a3f1a989aaf43446163a62f0a8ed34b0c010d0
  76. 59906b022adfc6f63903adbdbb64c82881e0b1664d6b7f7ee42319019fcb3d7e
  77. c9f2476bf8db102fea7310abadeb9e01
  78. 14296b21c6e2ba9d56759e2da4b09f58148852ddeefa8fb76a838a30871679a7
  79. 5022495104c280286e65184e3164f3f248356d065ad76acef48ee2ce244ffdc8
  80. 2f578cb0d97498b3482876c2f356035e3365e2c492e10513ff4e4159eebc44b8
  81. 457a2a8d0784e9fc8e49f6ef60f7f29e
  82. 01735bb47a933ae9ec470e6be737d8f646a8ec66
  83. 87e8230a9ca3f0c5ccfa56f70276e2f2
  84. 99a16ad0480bfa00adc470c6ccfa81e993023425
  85. 6502e8d9c49cc653563ea75f03958900543430be7b9c72e93fd6cf0ebd5271bc
  86. ffa73b9f9e650f50b8568a647a9a35cf
  87. dd2db9bfa45002375af028ac00ca1b5e0c1db30a116c21cac2b4c75cb4ff9aec
  88. b16e217cdca19e00c1b68bdfb28ead53b20adeabd6edcd91542f9fbf48942877
  89. c2e9fbca414575d5c080d97f378024a4d131d6e1262112aebaa96eafa3592381
  90. 2c89a18944d3a895bd6432415546635e
  91. fd3834d566a993c549a13a52d843a4e1
  92. b209dcdfdd030ae1944507fcd9ef0eaeabe22f21
  93. 646077aaf1ced1b32ae6519beced080f
  94. 992cb5a753697ee2642aa390f09326fcdb7fd59119053d6b1bdd35d47e62f472
  95. d8a44d2ed34b5fee7c8e24d998f805d9
  96. 8ea420d9aa341ba23cdea0ac03951bce866c933ba297268bc7db8a01ce8e9b8e
  97. 6ee94f6bdc4c4ed0fff621fec36c70ff093659ed
  98. 39aca59de3f2df6f1eefc57829d1138c001e2d03f3dc82cd5a55370fa97ec07b
  99. 682389250d914b95d6c23ab29dffee11cb65cae9
  100. f4062e52461b38ad9d9a4c936ed916f728968e85325c565233de4418f7e86dc6
  101. d419a9b17f7b4c23fd4e80a9bce130d2a13c307fccc4bfbc4d49f6b770d06d3b
  102. 20e3a0955baca4dc7f1f36d3b865e632474add77
  103. da92fc812b84137cef1571fb6c0285f0
  104. e2a24ab94f865caeacdf2c3ad015f31f23008ac6db8312c2cbfb32e4a5466ea2
  105. cc14df781475ef0f3f2c441d03a622ea67cd86967526f8758ead6f45174db78e
  106. 2f37912e7cb6e5c478e6dc3d0e381a24
  107. d61af007f6c792b8fb6c677143b7d0e2533394e28c50737588e40da475c040ee
  108. 3195c355aa564ea66b4b37baa9547cb53dde7cf4ae7010256db92fff0bde873d
  109. b85ed15756568b85148c1d432a8920f81e4b21f2bc38f0cf51d06ced619e0e77
  110. 59e1edf4d82fae4978e97512b0331b7eb21dd4b838b850ba46794d9c7a2c0983
  111. 20e1a0e96a210117dd728821dec8742ccfa5213d75e818c80d5bcc5aa8e91afc
  112. 1006fd38218b6769b39247e7306225b1cd001127
  113. a8460f446be540410004b1a8db4083773fa46f7fe76fa84219c93daa1669f8f2
  114. 0299e3c2536543885860c7b61e1efc3f
  115. e078778b62796bab2d7ab2b04d6b01bf
  116. 45de4b0457b2244f810d2793226f0ec27f252a35
  117. 8bcbf1c43d0550e4b8048137fbed5a7ab3c44ae4
  118. e889544aff85ffaf8b0d0da705105dee7c97fe26
  119. 3928c5874249cc71b2d88e5c0c00989ac394238747bb7638897fc210531b4aab
  120. 78147d3be7dc8cf7f631de59ab7797679aba167f82655bcae2c1b70f1fafc13d
  121. 47ec51b5f0ede1e70bd66f3f0152f9eb536d534565dbb7fcc3a05f542dbe4428
  122. be6c46239e9c753de227bf1f3428e271
  123. d7b487d2e840c4546661f497af0195614fc0906c03d187dc39815c811ea5ec3f
  124. a4839090ffea89bc9c9223d1f9cdeff2
  125. d8e8eb2714c91b9968ffd409f771e7e1
  126. 3ccb77a10497a32efcaa42ac646ca6cf
  127. 2ffe59a6a047b2333a1f3eb58753f3bc
  128. bc65ed919988c8e4b8f5a1cd371745456601700a
  129. 5d6b9e80e12bfc595d4d26f6afb099b3cb471dd4
  130. 78f86c3581ae893e17873e857aff0f0a82dcaed192ad82cd40ad269372366590
  131. 6f76505a91c91c29238f0ed70b369417
  132. b8c9c560c6970a877a7ad359f37811d7
  133. 6bc8e3505d9f51368ddf323acb6abc49
  134. c9abfc3e4da474e18795f5261f77e60c44e7b3353771281e4304e7506d56fdb4
  135. 7fbf758feaf4d992b16b26ac582a4bdcfc1a36b6f29b52fc713a2b8537f54202
  136. c966ace15bece19a119231dfaa2494f14200647fc7cb225667fb22cbb41436fd
  137. 30aa575986830b612630500bf2a96e619361a05a
  138. f18c7639dbb8644c4bca179243ee2a99
  139. 494ab44bb96537fc8a3e832e3cf032b0599501f96a682205bc46d9b7744d52ab
  140. abaf1d04982449e0f7ee8a34577fe8af
  141. 1e63a7186886deea6c4e5c2a329eab76a60be3a65bca1ba9ed6e71f9a46b7e9d
  142. 989f7eb4f805591839bcbc321dd44418eb5694d1342e37b7f24126817f10e37e
View full IOC feed500 total

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for medusalocker

CVE-2026-23760
CVE-2026-1731
CVE-2025-52691
CVE-2025-47176
CVE-2025-47171
CVE-2025-31324
CVE-2025-31161
CVE-2025-10035
CVE-2024-27199
CVE-2024-27198
CVE-2024-21887
CVE-2024-1709
CVE-2024-1708
CVE-2023-5129
CVE-2023-5009
CVE-2023-4966
CVE-2023-48788
CVE-2023-46805
CVE-2023-46748
CVE-2023-46747
CVE-2023-46604
CVE-2023-40044
CVE-2023-38831
CVE-2023-38035
CVE-2023-3519
CVE-2023-34039
CVE-2023-27351
CVE-2023-27350
CVE-2023-22515
CVE-2023-21529
CVE-2023-20198
CVE-2023-20109
Other

T1486

T1486

T1490

T1490

T1071

T1071

T1041

T1041

T1562

T1562

T1203

T1203

T1080

T1080

T1021

T1021

T1059

T1059

T1078

T1078

T1547

T1547

T1021.001

T1021.001

Victims(39)

CompanyDomainCountryIndustryStatusDiscovered
BAIAPAI
Claimed
16 days ago
dolrad
Claimed
22 days ago
Mairie Thiverval GrignonFR FranceGovernment & Defense
Claimed
22 days ago
sitgroupIT Italy
Claimed
23 days ago
BAEAOAI
Claimed
24 days ago
BAKAXAH
Claimed
24 days ago
BAEAXAI
Claimed
24 days ago
T Online
Claimed
26 days ago
FunkeScheid
Claimed
26 days ago
DadolightingManufacturing
Claimed
26 days ago
Sgs GmbhOther
Claimed
29 days ago
KarneslegalUS United StatesProfessional Services
Claimed
about 1 month ago
BATAZAI
Claimed
about 1 month ago
EstrelaIN IndiaTechnology
Claimed
about 1 month ago
BARAAAI
Claimed
about 1 month ago
BAPAMAI
Claimed
about 1 month ago
BAUARAI
Claimed
about 1 month ago
BAVADAI
Claimed
about 1 month ago
BAVACAIMY MalaysiaProfessional Services
Claimed
about 1 month ago
baralai
Claimed
about 1 month ago

Page 1 of 2