Activity timeline
MedusaLocker appears in 4 tracked threats between and ; the busiest month was 2026-07 with 2 reports.
ATT&CK techniques observed
- T1133 External Remote Services — Initial Accessobserved in 4 of 4 tracked threats
- T1190 Exploit Public-Facing Application — Initial Accessobserved in 4 of 4 tracked threats
- T1078 Valid Accounts — Initial Accessobserved in 3 of 4 tracked threats
- T1490 Inhibit System Recovery — Impactobserved in 3 of 4 tracked threats
- T1005 Data from Local System — Collectionobserved in 2 of 4 tracked threats
- T1021 Remote Services — Lateral Movementobserved in 2 of 4 tracked threats
- T1070 Indicator Removal — Stealth (formerly Defense Evasion)observed in 2 of 4 tracked threats
- T1110 Brute Force — Credential Accessobserved in 2 of 4 tracked threats
- T1486 Data Encrypted for Impact — Impactobserved in 2 of 4 tracked threats
- T1555 Credentials from Password Stores — Credential Accessobserved in 2 of 4 tracked threats
- T1566 Phishing — Initial Accessobserved in 2 of 4 tracked threats
- T1567 Exfiltration Over Web Service — Exfiltrationobserved in 2 of 4 tracked threats
- T1567.002 Exfiltration to Cloud Storage — Exfiltrationobserved in 2 of 4 tracked threats
- T1685 Disable or Modify Tools — Defense Impairmentobserved in 2 of 4 tracked threats
- T1003 OS Credential Dumping — Credential Accessobserved in 1 of 4 tracked threats
Tracked threats
- France Dark Web Threat Landscape: Ransomware and Hacktivist Activity Surges 4x Over 24 MonthsHIGH
- Team Cymru Infrastructure Analysis: Seven Active Ransomware Gangs (Akira, DragonForce, Clop, MedusaLocker, Qilin, INC Ransom, Lynx) Abuse Dual-Use Tools and Exploit SonicWall, Gladinet CentreStack, and FortiGate DevicesHIGH
- France Threat Landscape: Qilin/MedusaLocker/LockBit Ransomware and NoName057(16) Hacktivist DDoS Campaign Amid 4x Dark Web Activity SurgeHIGH
- Identity Attacks Overtake Exploits as Top Ransomware Cause (Sophos State of Ransomware 2026)