medusalocker
Known ransomware group ACTIVE Currently active
Medusa is a DDoS bot written in .NET 2.0. In its current incarnation its C&C protocol is based on HTTP, while its predecessor made use of IRC.
1
Total Claims
0
Critical
—
Records Claimed
0
Industries Hit
Active span: Sep 23, 2026 – Sep 23, 2026 · 1 organizations targeted
Currently active
Actor Threat Profile
Activity Timeline
Peak: Sep 2026 (1)Sep 2026
LessMore
Sep 2026Tradecraft & Infrastructure
0
Documented tools
1 / 1
MITRE tactics / techniques
5
Known leak sites