Active ransomware operator
← All groupsMedusa
aka MedusaLocker · 568 victims indexed · first seen 4 years ago · last activity 3 months ago
At a glance
- Status
- active
- Aliases
- MedusaLocker
- First seen
- 4 years ago
- Last activity
- 3 months ago
- Onion sites
- 14 known endpoints
- Primary sector
- Business Services · 64 hits
About
References
8 linksExternal sources curated by the MISP threat-intel community.
- ransomlook.io/group/medusa
- twitter.com/ThreatFabric/status/1285144962695340032
- threatfabric.com/blogs/partners-in-crime-medusa-cabassous.html
- threatfabric.com/blogs/the-rage-of-android-banking-trojans.html
- news.drweb.com/show/?i=10302&lng=en
- web.archive.org/web/20200509171721/https://raw.githubusercontent.com/fdiskyou/threat-INTel/master/2015/GlobalThreatIntelReport.pdf
- arbornetworks.com/blog/asert/medusahttp-ddos-slithers-back-spotlight/
- zerophagemalware.com/2017/10/13/rig-ek-via-malvertising-drops-a-miner/
Timeline
24 monthsTop countries
Top sectors
MITRE ATT&CK
4 techniques · 4 tacticsTactics
Indicators of compromise
Known tools
Detection · YARA rules
1 ruleMedusa_Ransomware
Detects Medusa/MedusaLocker ransomware
source: CISA AA25-071A
Recent victims
Loading…
Onion infrastructure
14 known- http://62foekhv5humjrfwjdyd2dgextpbf5i7obguhwvfoghmu3nxpkmxlcid.onion
- http://cx5u7zxbvrfyoj6ughw76oa264ucuuizmmzypwum6ear7pct4yc723qd.onion
- http://dlmfciajg5s4vliyo5dhs5jyzhi2xr2fnkebul46lpf4xudtqiue4nid.onion
- http://kyfiw76eol6ph2mq7pi5e5tdvce37bicddhai62qhdc5ja6jdchz4qqd.onion
- http://medusakxxtp3uo7vusntvubnytaph4d3amxivbggl3hnhpk2nmus34yd.onion
- http://medusaxko7jxtrojdkxo66j7ck4q5tgktf7uqsqyfry4ebnxlcbkccyd.onion
- http://medusaxko7jxtrojdkxo66j7ck4q5tgktf7uqsqyfry4ebnxlcbkccyd.onion/api/search?company=&page=0
- http://osintcorp.net
- http://qd7pcafncosqfqu3ha6fcx4h6sr7tzwagzpcdcnytiw3b6varaeqv5yd.onion
- http://s7lmmhlt3iwnwirxvgjidl6omcblvw2rg75txjfduy73kx5brlmiulad.onion
- http://xfv4jzckytb4g3ckwemcny3ihv4i5p4lqzdpi624cxisu35my5fwi5qd.onion
- http://xfv4jzckytb4g3ckwemcny3ihv4i5p4lqzdpi624cxisu35my5fwi5qd.onion/api/search?company=&page=0
- + 2 more endpoints
Source
Updated 3 months agoData on this page is sourced from the group's own leak posts, cross-checked with public ransomware trackers (RansomLook, ransomware.live, RansomWatch), MITRE ATT&CK, and our own Tor and Telegram crawlers. This is a public observatory page — share freely.
