Ransomware group profile · #73 by claimed victims
Medusalocker ransomware
Medusa is a DDoS bot written in .NET 2.0. In its current incarnation its C&C protocol is based on HTTP, while its predecessor made use of IRC.
Victimology
Who Medusalocker claims to have breached, from 94 leak-site posts recorded by VULONE.
Claims per month last 12 months
Top sectors
Top countries
Latest claimed victims 12 most recent
| Victim | Sector | Country | Claimed |
|---|---|---|---|
| 瑞祥机电 (Ruixiang Jidian) | Manufacturing | CN | 12 Sep 2026 |
| Abourametals abourametals.com | Manufacturing | AE | 12 Sep 2026 |
| Frisby Roofing (Frisby Construction LLC) frisbyconstruction.com | Other | US | 12 Sep 2026 |
| Praveg Caves Jawai | Hospitality | IN | 12 Sep 2026 |
| Licindia licindia.com | Other | IN | 2 Sep 2026 |
| Lawter lawter.com | Manufacturing | US | 1 Sep 2026 |
| Jgsee jgsee.kmutt.ac.th | Not Found | TH | 27 Aug 2026 |
| Servifruit servifruit.com | Agriculture and Food Production | MX | 27 Aug 2026 |
| Hungry Lion | Retail & E-Commerce | GH | 27 Aug 2026 |
| Qualisteel qualisteel.com | Manufacturing | — | 27 Aug 2026 |
| Health health.nsw.gov.au | Healthcare | AU | 27 Aug 2026 |
| Twal Family IT Lab | Technology | — | 16 Aug 2026 |
All 94 Medusalocker victims, searchable
Full victim list with claim posts, domains, timing and exports, plus the negotiation chats and leak-site screenshots VULONE archives for this crew.
Tactics, techniques and procedures
ATT&CK technique mapping for Medusalocker is in progress. Victimology, infrastructure status and leak-site tracking are live above.
Indicators, detections and the full playbook
Hashes, C2 addresses, onion services, Sigma and YARA detections per technique, and the negotiation transcripts are available to signed-in analysts.
Frequently asked
Is Medusalocker ransomware still active?
How many victims has Medusalocker claimed?
Which industries does Medusalocker target?
Which countries are most affected by Medusalocker?
Where does VULONE get Medusalocker victim data?
Other ransomware groups
Victim claims are collected from leak sites and enrichment partners (ransomware.live, RansomLook) and represent the group's own assertions, not confirmed breaches. Profile last updated 16 September 2026. Questions or corrections: [email protected].