A Windows ransomware that will run certain tasks to prepare the target system for the encryption of files. MedusaLocker avoids executable files, probably to avoid rendering the targeted system unusable for paying the ransom. It uses a combination of AES and RSA-2048, and reportedly appends extensions such as .encrypted, .bomber, .boroff, .breakingbad, .locker16, .newlock, .nlocker, and .skynet. 1 ransom note(s) on file
Objectives
Executive Summary
Ako is a medium-sophisticated criminal threat actor specializing in ransomware operations for financial gain. The group deploys MedusaLocker ransomware, which encrypts files using AES and RSA-2048 encryption while avoiding executable files to maintain system functionality. Ako targets organizations seeking financial gain through ransom payments, focusing on sectors and countries where data value is high.
Goals & Targeting
Ako's primary objectives are organizational-gain through ransomware campaigns. Targets include industries with valuable data and higher willingness to pay ransoms, such as healthcare, finance, and legal sectors. The group likely selects victims based on their ability to disrupt operations and extract maximum financial benefits from ransoms.
Enhanced Description
Ako operates as a criminal threat actor group primarily motivated by financial gain, employing the MedusaLocker ransomware. This ransomware encrypts victim files with strong encryption algorithms (AES and RSA-2048) while avoiding executable files to prevent rendering systems unusable, which could deter victims from paying ransoms. The malware appends various extensions to encrypted files, making it identifiable. Ako's operations are characterized by strategic approach in targeting sectors and countries where data theft or encryption yields significant financial returns.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Ako's campaigns are characterized by targeted, stealthy operations to avoid detection. Their use of strong encryption and avoidance of disrupting system functionality make their attacks more persistent. Campaign patterns likely involve phishing emails or exploit kits for initial access. Ako has conducted campaigns focusing on smaller businesses with sufficient data value but limited defenses.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Medium confidence in Ako's operational details due to limited specific campaign reports. Data gaps include exact targeting criteria and specific tools used.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics