MedusaLocker Ransomware
First observed in early September 2019, MedusaLocker is a ransomware tool targeting users globally.
Summary
First observed in early September 2019, MedusaLocker is a ransomware tool targeting users globally.
Affected platforms
The following platforms are known to be affected:
Threat details
At the time of publication, it is unclear how MedusaLocker is delivered, although there are unconfirmed reports indicating it may be delivered via watering hole attacks.
Once installed, MedusaLocker will create registry keys to maintain persistence and provide access to mapped storage, before then removing or disabling any recovery services. It will then attempt to encrypt all reachable non-system files using a hybrid AES-RSA scheme.
Remediation steps
| Type | Step |
|---|---|
|
If a device on your network becomes infected with ransomware it will begin encrypting local machine files and files on any network the logged-in user has permission to access. For system administration accounts this may include backup storage locations. To avoid becoming infected with ransomware, ensure that:
Identifying the source of infection:
To limit the damage of ransomware and enable recovery:
|
Last edited: 14 February 2020 2:57 pm