ME

medusalocker

Known ransomware group ACTIVE
Currently active

Medusa is a DDoS bot written in .NET 2.0. In its current incarnation its C&C protocol is based on HTTP, while its predecessor made use of IRC.

1

Total Claims

0

Critical

Records Claimed

0

Industries Hit

Active span: Sep 23, 2026 – Sep 23, 2026 · 1 organizations targeted

Currently active
Activity 1.9 Severity 2.5 Sectors 0.0 Tooling 0.2

Actor Threat Profile

Activity Timeline

Peak: Sep 2026 (1)
Sep 2026
LessMore
Sep 2026

Share this profile

Shareable intel card for medusalocker

Tradecraft & Infrastructure

0

Documented tools

1 / 1

MITRE tactics / techniques

5

Known leak sites

Full intelligence profile on ransomware.live →

Targeted Organizations

Claims by medusalocker

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.