MedusaLocker has claimed 16 victims since surfacing on the tracker in early July, with five in the past month alone, concentrating on manufacturing, technology, and public sector targets and showing a clear European tilt, Germany accounts for a quarter of claimed hits, with France and Canada following. The group is described in its own materials in terms borrowed from an unrelated DDoS bot lineage, a mismatch that suggests the public-facing description is unreliable and should not be taken as an accurate technical profile. Catalogued ATT&CK behavior associated with this ransomware family includes disabling security tooling and shadow copy deletion prior to encryption, alongside network share enumeration to spread laterally before deploying payloads. Victim naming this week spans IT services, dry cleaning, industrial manufacturing, and courier logistics, indicating opportunistic targeting rather than sector specialization. Claimed activity has been steady rather than spiking, consistent with a mid-tier double-extortion operation cycling through small and mid-sized organizations across Western Europe and North America.