Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors medusalocker

Description

Medusa is a DDoS bot written in .NET 2.0. In its current incarnation its C&C protocol is based on HTTP, while its predecessor made use of IRC. Known victims: 51 1 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Medusalocker is a medium-sophistication criminal threat actor targeting organizations for financial gain primarily through ransomware campaigns. Active since November 2021, the group has demonstrated persistent activity with 51 known victims across various sectors. Their operations are notable for using DDoS botnets and have evolved significantly over time.

Goals & Targeting

Medusalocker’s primary objectives are financial gain through ransomware campaigns and disrupting business operations via DDoS attacks. The group targets a wide range of sectors to maximize their attack surface and potential revenue. Their victims have included businesses in industries such as retail, finance, healthcare, and education, indicating a strategic approach to targeting high-value or易于受到攻击的组织.

Enhanced Description

Medusalocker is a prominent cybercriminal group known for deploying ransomware and conducting large-scale cyberattacks, primarily targeting financial institutions. The group's operations date back to 2021, making them a relatively established threat actor in the cybercrime landscape. Medusalocker has targeted numerous sectors, including finance, education, healthcare, and retail, among others. Their TTPs include the use of DDoS botnets, which are often used as part of their attack campaigns to disrupt victim organizations and increase the likelihood of successful ransom payments. The group's operational tactics have evolved since its inception, with a particular focus on enhancing the scope and impact of attacks. Medusalocker has been linked to multiple high-profile incidents, including attacks on Elkind Sdn Bhd, Strategic Imports, Magnolia (Israel), Trimble Inc., and several others.

Key Capabilities

  • .NET-based DDoS botnet
  • Ransomware deployment
  • Coordinated DDoS attacks
  • Use of HTTP-based C2 infrastructure

MITRE ATT&CK Tactics

Initial Access
Defense Evasion
Credential Access
Discovery
Lateral Movement

ATT&CK Techniques

T1560.004
T1527
T1518
T1059
T1036

Software / Tooling

Medusa Botnet
Custom Ransomware

Campaigns & Victims

Medusalocker has conducted numerous campaigns, leveraging DDoS attacks, ransomware, and data exfiltration to disrupt victim organizations. Their operational tempo is steady, with a focus on high-value targets across multiple industries. Notable past operations include attacks against financial institutions and educational organizations in various countries. The group often stages initial attacks to gauge organizational resilience before deploying ransomware.

IOC Patterns

  • Use of .NET-based DDoS bots
  • HTTP-based C2 communication
  • Hashes associated with Medusa botnet files
  • Spear-phishing emails delivered via legitimate-looking domains

Recommended Actions

  • Implement network traffic monitoring to detect DDoS activity.
  • Use EDR solutions to identify and block Medusa-related malware patterns.
  • Apply regular system updates and patches to mitigate exploit vectors.
  • Train users to recognize phishing attempts targeting their organization.
  • Back up critical systems regularly to avoid ransomware extortion.

Suggested Tags

ransomware
DDoS
criminal
financial-gain

Confidence Assessment

Low to moderate confidence in the actor's exact motivations beyond financial gain. Limited visibility into specific TTPs and infrastructure details creates gaps in full operational understanding, though their activity is well-documented in multiple campaigns.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

SHA-256 Hash 19
SHA-256 Hash 19
2eddfe711c32ef1668e14a10d00452c83c29e394e17c41f491550a1583c1bcac
75% TLP:CLEAR
759b96f44806578cc0836a3a2bf11c8bc553effac72f8d28b94aec78b66be906
75% TLP:CLEAR
9f066975f1e02b29c7c635280f405c59704ce4f4e06b04e9ac8a7eac22acd3c7
75% TLP:CLEAR
8bc455e5de35290f8a94376357947bd72aaf6f4d452c25a8ef444e037ef76b9f
75% TLP:CLEAR
d00f7cf6af68ba832b9d364f28411346cfe66fd3b1f5bcac318766add29ff7f0
75% TLP:CLEAR
1f2df15442593b159e45d16a27e4d43d3a9062da212a588ba4c048f214a0b7be
75% TLP:CLEAR
1e9246e6a35731143368eaa0ade4f3cf576d6b22e6090152f6e94f1fa3070651
75% TLP:CLEAR
6ae3a58a78be9c606009c657de4e390538b21ad951e62b6f4d31138e1a75732c
75% TLP:CLEAR
33a8024395c56fab4564b9baef1645e505e00b0b36bff6fad3aedb666022599a
75% TLP:CLEAR
b8c994e3ed7dcc9080916119ddc315533c129479f508676d7544b82b2e24745f
75% TLP:CLEAR
63eb3d2886d9cb880c9b0d54b94f3e149b3b5b6215a33a0ef63588a09dcd4499
75% TLP:CLEAR
270c3354b3ee2940b499e365eaba143fba9d458f434dc38e663dc0f08e96121e
75% TLP:CLEAR
48046fb0e566f5a2d184f84b76d6cadc458762556daed0ae4a3a1200afbefb54
75% TLP:CLEAR
c0c726a23111c220d022fcd01a85f9788249e42baece03f83b6059170453b801
75% TLP:CLEAR
012657c4548d9c98223caa4cc7aa52fc083d6983d42fde16ca3271412e7fe3fe
75% TLP:CLEAR
8edbb1944d94ff91ee917c31590b6d1d5690a52fc153e44355ee9749aa0f4625
75% TLP:CLEAR
364f1b7466d8e4c9f55294ecf1f874c763bcf980c59b0250c613ac366def6aca
75% TLP:CLEAR
5d5d639fdfbf632bb7d9f1bb28731217d09d36078ab5e594baf2a5a41267a5d2
75% TLP:CLEAR
dc4840a0992b218cbedd5a7ac5c711cb98f1f9e78a8ffdea37c694061dfd34c6
75% TLP:CLEAR

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

27

Campaigns

19

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Critical Infrastructure
Backdoor / C2
DDoS
ransomware
criminal
financial-gain

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Nov 3, 2021
Last Seen
Jul 7, 2026
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.