Ransomware crew infects 100+ orgs monthly with new MedusaLocker variant
ID: 00020a56-4698-5163-84b3-9f30bdaa2748
STIX ID: report--00020a56-4698-5163-84b3-9f30bdaa2748
Feed Name: The Register (Security)
The report details research by Cisco Talos linking an extortionist called "PaidMemes" to a MedusaLocker variant (BabyLockerKZ) that has infected hundreds of organizations (primarily SMBs) since 2022; the actor uses publicly available tooling and credential-stealing components (Mimikatz/rclone wrappers, Checker/Mimik) to harvest credentials, stores tooling on user folders, and leaves identifiers like "paid_memes" in PDB/registry keys that allowed investigators to enumerate victims and samples.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
