Skip to main content
Ransomware Group

Ako

A Windows ransomware that will run certain tasks to prepare the target system for the encryption of files. MedusaLocker avoids executable files, probably to avoid rendering the targeted system unusable for paying the ransom. It uses a combination of AES and RSA-2048, and reportedly appends extensions such as .encrypted, .bomber, .boroff, .breakingbad, .locker16, .newlock, .nlocker, and .skynet.

Known victims0

Threat Level

LOW

Known Infrastructure

The following Tor hidden services have been associated with this group:

  • kwvhrdibgmmpkhkidrby4mccwqpds5za6uo2thcw5gz75qncv7rbhyad.onion

Warning: These are malicious sites. Do not visit without proper security measures.

0

Check If You’re Affected

Search our database to see if your organization appears in Ako’s victim list.

Try it nowFree⌘K
Try

risk score · threat categories · sources · age · confidence — in one request