Threat actor believed to be spreading new MedusaLocker variant since 2022
ID: 45953968-d8c0-5da5-ae59-c0370c741fa2
STIX ID: report--45953968-d8c0-5da5-ae59-c0370c741fa2
Feed Name: Cisco Talos
Threat Score
# Executive summary Cisco Talos attributes a financially motivated affiliate-like threat actor active since at least 2022 that deploys a MedusaLocker variant named BabyLockerKZ, describing its credential-theft and lateral-movement toolset (including a "paid_memes" developer fingerprint), victim distribution (notably Europe then Latin America), and providing IOCs and mitigation guidance to detect and block infections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
