Medusa is a DDoS bot written in .NET 2.0. In its current incarnation its C&C protocol is based on HTTP, while its predecessor made use of IRC. Known victims: 51 1 ransom note(s) on file
Objectives
Executive Summary
Medusalocker is a medium-sophistication criminal threat actor targeting organizations for financial gain primarily through ransomware campaigns. Active since November 2021, the group has demonstrated persistent activity with 51 known victims across various sectors. Their operations are notable for using DDoS botnets and have evolved significantly over time.
Goals & Targeting
Medusalocker’s primary objectives are financial gain through ransomware campaigns and disrupting business operations via DDoS attacks. The group targets a wide range of sectors to maximize their attack surface and potential revenue. Their victims have included businesses in industries such as retail, finance, healthcare, and education, indicating a strategic approach to targeting high-value or易于受到攻击的组织.
Enhanced Description
Medusalocker is a prominent cybercriminal group known for deploying ransomware and conducting large-scale cyberattacks, primarily targeting financial institutions. The group's operations date back to 2021, making them a relatively established threat actor in the cybercrime landscape. Medusalocker has targeted numerous sectors, including finance, education, healthcare, and retail, among others. Their TTPs include the use of DDoS botnets, which are often used as part of their attack campaigns to disrupt victim organizations and increase the likelihood of successful ransom payments. The group's operational tactics have evolved since its inception, with a particular focus on enhancing the scope and impact of attacks. Medusalocker has been linked to multiple high-profile incidents, including attacks on Elkind Sdn Bhd, Strategic Imports, Magnolia (Israel), Trimble Inc., and several others.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Medusalocker has conducted numerous campaigns, leveraging DDoS attacks, ransomware, and data exfiltration to disrupt victim organizations. Their operational tempo is steady, with a focus on high-value targets across multiple industries. Notable past operations include attacks against financial institutions and educational organizations in various countries. The group often stages initial attacks to gauge organizational resilience before deploying ransomware.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Low to moderate confidence in the actor's exact motivations beyond financial gain. Limited visibility into specific TTPs and infrastructure details creates gaps in full operational understanding, though their activity is well-documented in multiple campaigns.
No techniques linked yet.
No tools linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
27
Campaigns
19
IOCs
0
Observed Data
0
Tactics