Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Medusalocker

Medusa is a DDoS bot written in .NET 2.0. In its current incarnation its C&C protocol is based on HTTP, while its predecessor made use of IRC.
External information

Victims
 

49

First Discovered
victim

2022-11-15

Last Discovered
victim

2025-05-30

Avg Delay
between attack and claim

88.2 days

Infostealer
for victim with domain

0.0%

View Victims on World Map


Known Locations (4)
Favicon Title Type Available Last Visit FQDN
favicon None No 2025-06-01 21:19:12 qd7pcafncosqfqu3ha6fcx4h6sr7tzwagzpcdcnytiw3b6varaeqv5yd.onion
favicon Ransomware blog – We will not give ourselves a name. Just watch out for the leakage of your data:) Yes 2025-06-15 17:31:27 z6wkgghtoawog5noty5nxulmmt2zs7c3yvwr22v4czbffdoly2kl4uad.onion
favicon Medusa Chat No 2025-06-01 21:20:10 95.143.191.148:3000
favicon Human Verify No 2025-06-01 21:20:46 medusaxko7jxtrojdkxo66j7ck4q5tgktf7uqsqyfry4ebnxlcbkccyd.onion

Target (Available)
Top 5 Activity Sectors
  • Technology 1
  • Business Services 1
  • Manufacturing 1
  • Healthcare 1
  • Hospitality and Tourism 1
Top 5 Countries
  • US flag United States 3
  • AE flag United Arab Emirates 1
  • HU flag Hungary 1
  • DE flag Germany 1
  • CO flag Colombia 1

Heatmap (Available)

Ransom Notes (1)

Tools Used (Available)
This information is provided by Ransomware-Tool-Matrix
Discovery RMM Tools Defense Evasion Credential Theft OffSec Networking LOLBAS Exfiltration
Advanced IP Scanner

Advanced Port Scanner

SoftPerfect NetScan
Remote Desktop Plus (RDP+)


HRSword

PCHunter

ProcessHacker
Invoke-TheHash

Mimikatz

Impacket




PsExec





Vulnerabilities Exploited (0)

No vulnerabilities exploited available.


TTPs Matrix (0)

No TTPs available.


Negotiation Chats (0)

No negotiation chats available.


YARA Rules (1)

Indicators of Compromise (IoCs) (0)

No IoCs available for this group.


Victims (49)
Logo
UnigazJordan Medusalocker
Discovery Date: 2025-05-30
www.unigaz.net $690.6 Million The list of files is available at the link https://dropmefiles.com/9HG...
JO
Logo
Mulia Raya Medusalocker
Discovery Date: 2025-05-29
www.muliaraya.co.id $34.8 Million The list of files is available at the link https://dropmefiles.com...
ID
Logo
Curtain Bluff Medusalocker
Discovery Date: 2025-03-25
www.curtainbluff.com Curtain Bluff files Vacationer information (personal data), audit information (...
AG
Logo
Inversiones Clinica Del Meta SA Medusalocker
Discovery Date: 2025-02-28
www.clinicameta.co Description employee information – patient information – agreements – password da...
CO
Logo
MICRO MANUFACTRING Medusalocker
Discovery Date: 2025-02-12
Estimated Attack Date: 2025-02-06
Micro Manufacturing Inc. Descriptionemployee information – agreement – customer email(.xls)-.msg out...
Logo
bendixengineering Medusalocker
Discovery Date: 2025-01-09
Descriptionemployee information – agreement – customer email(.xls)-.msg outlook files Data-2016-2024...
US
Logo
SILKNET COMPANY Medusalocker
Discovery Date: 2024-11-26
URL:https://silknet.com https://geocell.ge/ On sale:Company email base(about 1tb)Customer dataCompan...
US
Logo
Protected: HIDE NAME Medusalocker
Discovery Date: 2024-05-09
There is no excerpt because this is a protected post....
Logo
SHAMASS.ORG Medusalocker
Discovery Date: 2024-05-02
Estimated Attack Date: 2024-04-22
Descriptionemployee information – agreement – customer email(.xls)-.msg outlook files Price-$50000 (...
US
Logo
Protected: HIDE NAME SELL DATA SOON Medusalocker
Discovery Date: 2024-04-26
Estimated Attack Date: 2024-04-25
There is no excerpt because this is a protected post....
Logo
Protected: Name is hidden Medusalocker
Discovery Date: 2023-11-29
There is no excerpt because this is a protected post....
Logo
skalar.com Medusalocker
Discovery Date: 2023-11-29
There is no excerpt because this is a protected post....
Logo
Ada-Borup-West School Medusalocker
Discovery Date: 2023-10-23
Descriptionemployee information – student information – all contracts Price: 35000$...
Logo
wellons.org Medusalocker
Discovery Date: 2023-10-23
Descriptionemployee information – agreement – customer email(.xls)- pst files 15+GB all outlook mess...
Logo
Confidential files Medusalocker
Discovery Date: 2023-10-02
A large number of documents of large companies are available for sale Revenue-$10-$70kk Financial do...
Logo
INSULCANA CONTRACTING LTD Medusalocker
Discovery Date: 2023-08-03
Estimated Attack Date: 2023-07-27
Descriptionemployee information – agreement – customer email(.xls)- passport all canada and other do...
Logo
Protected: INSULCANA CONTRACTING LTD Medusalocker
Discovery Date: 2023-07-27
There is no excerpt because this is a protected post....
Logo
Protected: Hidden name Medusalocker
Discovery Date: 2023-07-17
There is no excerpt because this is a protected post....
Logo
Hoosier Equipment company Medusalocker
Discovery Date: 2023-07-04
DescriptionClient Case – agreement – email(.msg)- and other documents Price: 60000$...
Logo
Ucamco Belgium Medusalocker
Discovery Date: 2023-07-02
DescriptionClient Case – customers email-Audit information-There is also access to email for newslet...
Logo
reutlingen.ihk.de Medusalocker
Discovery Date: 2023-06-24
Estimated Attack Date: 2023-06-16
DescriptionClient Case – agreement – email(.msg)- contracts – and other documents PRICE-$80000...
DE
Logo
Hausamman company Medusalocker
Discovery Date: 2023-06-24
Estimated Attack Date: 2023-06-16
DescriptionClient Case – customers email-documents PRICE-$20000...
Logo
kafflogistic.hu Medusalocker
Discovery Date: 2023-06-24
Estimated Attack Date: 2023-06-17
DescriptionClient Case – agreement – email(outlook files)- contracts – and other documents PRICE-$50...
HU
Logo
SELL DATA(qtox) Medusalocker
Discovery Date: 2023-06-24
Estimated Attack Date: 2023-06-17
Available for sale: to buy please contact qtox price negotiable qtox-E9CD65687463F67F64937E961DD723D...
Logo
Jalux Americas, Inc. Medusalocker
Discovery Date: 2023-06-14
Estimated Attack Date: 2021-11-03
DescriptionClient Case – agreement – email(.msg) – and other documents Price: 160000$The company fai...
Logo
arborsct.com Medusalocker
Discovery Date: 2023-06-14
DescriptionClient Case – agreement – email(.msg)- and other documents Price: 60000$ One copy will be...
Logo
Salmon Software Medusalocker
Discovery Date: 2023-06-03
Estimated Attack Date: 2022-07-11
DescriptionClient Case – agreement – email(.msg)- passport- and other documents Price: 120000$ Three...
Logo
LETAPE JEUNES Medusalocker
Discovery Date: 2023-06-03
Estimated Attack Date: 2023-06-02
DescriptionClient Case – agreement – email(.msg)- contracts – and other documents(passports) PRICE-$...
Logo
bsw-architects.com Medusalocker
Discovery Date: 2023-04-11
DescriptionClient Case – agreement – email(.msg)- contracts – and other documents PRICE-$80000 There...
Logo
DGLEGAL Medusalocker
Discovery Date: 2022-11-15
N/A
Logo
emscrm Medusalocker
Discovery Date: 2022-11-15
N/A
Logo
MIDAS Company Medusalocker
Discovery Date: 2022-11-15
N/A
Logo
fidelityunited.ae Medusalocker
Discovery Date: 2022-11-15
N/A
AE
Logo
goldcreekfoods Medusalocker
Discovery Date: 2022-11-15
N/A
Logo
exheat.com Medusalocker
Discovery Date: 2022-11-15
N/A
Logo
hwrpc.com Medusalocker
Discovery Date: 2022-11-15
N/A
Logo
tristatefabricators_inc Medusalocker
Discovery Date: 2022-11-15
N/A
Logo
atlantisholidays Medusalocker
Discovery Date: 2022-11-15
N/A
Logo
archimages inc Medusalocker
Discovery Date: 2022-11-15
N/A
Logo
ALTlTUDE AEROSPACE INC Medusalocker
Discovery Date: 2022-11-15
N/A
Logo
Fonderia Boccacci Medusalocker
Discovery Date: 2022-11-15
N/A
Logo
Zelena Laguna Hotel Medusalocker
Discovery Date: 2022-11-15
N/A
Logo
LEGAZPIBANK Medusalocker
Discovery Date: 2022-11-15
N/A
Logo
MCCLEAN16 company Medusalocker
Discovery Date: 2022-11-15
N/A
Logo
lawtrade company Medusalocker
Discovery Date: 2022-11-15
N/A
Logo
Autosoft company Medusalocker
Discovery Date: 2022-11-15
N/A
Logo
BIOPLAN Medusalocker
Discovery Date: 2022-11-15
N/A
Logo
Dyatech company Medusalocker
Discovery Date: 2022-11-15
N/A