Skip to main content
Back to Ransomware Database
Ransomware Group

medusalocker

Medusa is a DDoS bot written in .NET 2.0. In its current incarnation its C&C protocol is based on HTTP, while its predecessor made use of IRC.

Known victims90

Threat Level

MEDIUM

Tactics, Techniques & Procedures (TTPs)

CredentialTheft

  • Invoke-TheHash
  • Mimikatz

DefenseEvasion

  • HRSword
  • PCHunter
  • ProcessHacker

DiscoveryEnum

  • Advanced IP Scanner
  • Advanced Port Scanner
  • SoftPerfect NetScan

LOLBAS

  • PsExec

Offsec

  • Impacket

RMM-Tools

  • Remote Desktop Plus (RDP+)
0

Check If You’re Affected

Search our database to see if your organization appears in medusalocker’s victim list.

Try it nowFree⌘K
Try

risk score · threat categories · sources · age · confidence — in one request