logo

Ransomware crew infects 100+ orgs monthly with new MedusaLocker variant

ID: 00020a56-4698-5163-84b3-9f30bdaa2748

STIX ID: report--00020a56-4698-5163-84b3-9f30bdaa2748

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2024-10-03

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

The report details research by Cisco Talos linking an extortionist called "PaidMemes" to a MedusaLocker variant (BabyLockerKZ) that has infected hundreds of organizations (primarily SMBs) since 2022; the actor uses publicly available tooling and credential-stealing components (Mimikatz/rclone wrappers, Checker/Mimik) to harvest credentials, stores tooling on user folders, and leaves identifiers like "paid_memes" in PDB/registry keys that allowed investigators to enumerate victims and samples.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.