logo

Threat actor believed to be spreading new MedusaLocker variant since 2022

ID: 45953968-d8c0-5da5-ae59-c0370c741fa2

STIX ID: report--45953968-d8c0-5da5-ae59-c0370c741fa2

Feed Name: Cisco Talos

Threat Score
80/100

Date Published: 2024-10-03

Date Updated: 2026-04-27

Author: Tiago Pereira

...
...

# Executive summary Cisco Talos attributes a financially motivated affiliate-like threat actor active since at least 2022 that deploys a MedusaLocker variant named BabyLockerKZ, describing its credential-theft and lateral-movement toolset (including a "paid_memes" developer fingerprint), victim distribution (notably Europe then Latin America), and providing IOCs and mitigation guidance to detect and block infections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.