Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Description

A Windows ransomware that will run certain tasks to prepare the target system for the encryption of files. MedusaLocker avoids executable files, probably to avoid rendering the targeted system unusable for paying the ransom. It uses a combination of AES and RSA-2048, and reportedly appends extensions such as .encrypted, .bomber, .boroff, .breakingbad, .locker16, .newlock, .nlocker, and .skynet. 1 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Ako is a medium-sophisticated criminal threat actor specializing in ransomware operations for financial gain. The group deploys MedusaLocker ransomware, which encrypts files using AES and RSA-2048 encryption while avoiding executable files to maintain system functionality. Ako targets organizations seeking financial gain through ransom payments, focusing on sectors and countries where data value is high.

Goals & Targeting

Ako's primary objectives are organizational-gain through ransomware campaigns. Targets include industries with valuable data and higher willingness to pay ransoms, such as healthcare, finance, and legal sectors. The group likely selects victims based on their ability to disrupt operations and extract maximum financial benefits from ransoms.

Enhanced Description

Ako operates as a criminal threat actor group primarily motivated by financial gain, employing the MedusaLocker ransomware. This ransomware encrypts victim files with strong encryption algorithms (AES and RSA-2048) while avoiding executable files to prevent rendering systems unusable, which could deter victims from paying ransoms. The malware appends various extensions to encrypted files, making it identifiable. Ako's operations are characterized by strategic approach in targeting sectors and countries where data theft or encryption yields significant financial returns.

Key Capabilities

  • Ransomware deployment (MedusaLocker)
  • Strong encryption using AES/RSA-2048
  • Targeted attacks on vulnerable organizations
  • Avoidance of executable files to maintain system functionality

MITRE ATT&CK Tactics

Initial Access
Execution
Data Destruction/Cessation
Reconnaissance

ATT&CK Techniques

T1059.003
T1078
T1486
T1055

Software / Tooling

Custom Ransomware (MedusaLocker)
Spear-phishing Tools
Network Monitoring Utilities

Campaigns & Victims

Ako's campaigns are characterized by targeted, stealthy operations to avoid detection. Their use of strong encryption and avoidance of disrupting system functionality make their attacks more persistent. Campaign patterns likely involve phishing emails or exploit kits for initial access. Ako has conducted campaigns focusing on smaller businesses with sufficient data value but limited defenses.

IOC Patterns

  • Spear-phishing emails with malicious attachments
  • Execution of MedusaLocker ransomware
  • File encryption with .encrypted, .bomber, etc.
  • Network traffic analysis for C2 communication

Recommended Actions

  • Implement robust email filtering to detect phishing attempts.
  • Monitor network traffic for signs of ransomware activity.
  • Enhance endpoint detection and response capabilities.
  • Regularly back up data and store it offline securely.

Suggested Tags

Ransomware
Financial-Crime

Confidence Assessment

Medium confidence in Ako's operational details due to limited specific campaign reports. Data gaps include exact targeting criteria and specific tools used.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Financial-Crime

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.