Skip to content
The Nexus
Group profile5 claimed in last 30d16 total tracked

medusalocker

Forward this

Medusa is a DDoS bot written in .NET 2.0. In its current incarnation its C&C protocol is based on HTTP, while its predecessor made use of IRC.

First seen: Jul 1 · 22:28 UTCLast seen: Aug 16 · 15:21 UTCTracked since: 2022-11-15
Sectors hit
  • Manufacturing3
  • Technology2
  • Public Sector2
  • Unspecified2
  • Business Services2
  • Transportation1
  • Telecommunication1
  • Retail & E-Commerce1
Countries hit
  • Germany4
  • France2
  • Canada2
  • South Africa1
  • United Kingdom1
  • Switzerland1
  • Brazil1
  • United Arab Emirates1
MITRE ATT&CK · observed TTPs1 tactic

Tactics and techniques attributed to MEDUSALOCKER by ransomware.live's curated TTP catalog. Identifiers link to the canonical MITRE ATT&CK reference for each tactic or sub-technique.

Recent claimed victims
TechnologyAug 16 · 15:21 UTC

Twal Family IT Lab

Retail & E-CommerceUnited KingdomAug 16 · 15:21 UTC

All Parts Dry Cleaning

allpartsdrycleaning.co.uk
TechnologyGermanyAug 16 · 15:20 UTC

Idex Group

idex-group.com
ManufacturingFranceAug 16 · 15:20 UTC

Bija Industrie

bija-industrie.com
TransportationSouth AfricaAug 16 · 15:19 UTC

Thecourierguy

thecourierguy.co.za
Consumer ServicesBrazilJul 1 · 22:33 UTC

Estrela

estrela.ind
Business ServicesJul 1 · 22:33 UTC

Karneslegal

karneslegal.com
Business ServicesGermanyJul 1 · 22:32 UTC

Sgs Gmbh

sgs-gmbh.com
ManufacturingJul 1 · 22:32 UTC

Dadolighting

dadolighting.com
TelecommunicationGermanyJul 1 · 22:31 UTC

T Online

t-online.de
ManufacturingGermanyJul 1 · 22:31 UTC

FunkeScheid

FunkeScheid.com
Public SectorFranceJul 1 · 22:30 UTC

Mairie Thiverval Grignon

mairie-thiverval-grignon.fr
United Arab EmiratesJul 1 · 22:30 UTC

Dolrad

dolrad.ae
HealthcareSwitzerlandJul 1 · 22:29 UTC

Bd

bd.zh.ch
Public SectorCanadaJul 1 · 22:28 UTC

Penticton and District Society for Community Living

pdscl.org