Ransomware Group
Ako
A Windows ransomware that will run certain tasks to prepare the target system for the encryption of files. MedusaLocker avoids executable files, probably to avoid rendering the targeted system unusable for paying the ransom. It uses a combination of AES and RSA-2048, and reportedly appends extensions such as .encrypted, .bomber, .boroff, .breakingbad, .locker16, .newlock, .nlocker, and .skynet.
Known victims0
Threat Level
LOW
Known Infrastructure
The following Tor hidden services have been associated with this group:
kwvhrdibgmmpkhkidrby4mccwqpds5za6uo2thcw5gz75qncv7rbhyad.onion
Warning: These are malicious sites. Do not visit without proper security measures.
Check If You’re Affected
Search our database to see if your organization appears in Ako’s victim list.
Try it nowFree⌘K
Try
risk score · threat categories · sources · age · confidence — in one request