Technical profile · CISA
MedusaLocker
A source profile referencing AA22-181A; not an attribution conclusion for a specific case.
- Name / status
- MedusaLocker · Confirmed (source profile)
- Aliases
- Aliases have not been validated in this profile. Medusa and MedusaLocker are separate profiles; do not merge the names.
- Description
- CISA and its partners published advisory AA22-181A on MedusaLocker, covering behaviors, indicators and mitigation measures.
- First Seen
- The date has not been standardized in the V1 profile
- Current Activity
- No verified current activity dataset is available
- Target sectors
- Reviewed sector categories have not yet been entered
- Platforms
- Cross-check against the variant/sample in the advisory
- Extensions / ransom note names
- See source documentation; do not use these indicators alone for attribution
- Known TTP / MITRE ATT&CK
- The advisory contains technical details; a separate mapping has not yet been entered into V1
- IOC
- Cross-check only indicators with a source, timestamp and context
- Encryption / Full / Partial
- No independent measurements on Ransomware.VN samples are available
- Public decryptor status
- Unknown — no tool with a validated scope is available in the V1 directory
- Recovery Intelligence
- No validated public recovery observations are available. NAS, SQL and VMs require checks of structure, logs and integrity; no recovery rate is stated.
- Last Updated
- 09/10/2026 (UTC+7)