MedusaLocker
MedusaLocker is a ransomware operation referenced in the provided content as being known for double extortion and for continuing to target manufacturing and critical infrastructure. The content links MedusaLocker to affiliate intrusions in which EDR-killing and defense-evasion tooling is used prior to ransomware deployment. Specifically, ThrottleBlood has been repeatedly observed in MedusaLocker intrusions, and ProcessKO and 0th3r_av5.exe are described as process-killing tools frequently seen in MedusaLocker attacks to shut down antivirus monitoring. The content also notes overlap between MedusaLocker and other ransomware ecosystems: LockBit reportedly uses a very similar service-kill list, and custom cryptocurrency mixing services are mentioned in connection with MedusaLocker. In broader telemetry on commercial EDR killers, CardSpaceKiller is linked to intrusions involving MedusaLocker, and AbyssKiller is reported in use by affiliates of Medusa, DragonForce, and BlackSuit, but the content does not directly attribute AbyssKiller to MedusaLocker itself. Known alias in the provided content: medusalocker.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
47 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Recent activity
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a threat actor/group in whose intrusions the ThrottleBlood tool appeared.
Referenced as a ransomware group whose affiliates repeatedly used ThrottleBlood.
Ransomware activity associated with process-killing tools used to disable antivirus monitoring before payload execution.
Ransomware group observed deploying CardSpaceKiller during incidents.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.