logo

MedusaLocker Ransomware Will Bypass Most Antivirus Software

ID: ff50e709-1c95-5d6d-baf0-71406426924f

STIX ID: report--ff50e709-1c95-5d6d-baf0-71406426924f

Feed Name: WatchGuard Secplicity Blog

Threat Score
75/100

Date Published: 2020-05-19

Date Updated: 2026-05-01

Author: The Editor

...
...

A MedusaLocker ransomware variant (or copycat) was observed using a malicious batch file to disable Windows Defender in Safe Mode (deleting the SafeBoot WinDefend registry key), install itself as a service named "backupvt" configured for Safe Mode Minimal, force a reboot into Safe Mode, and then run to encrypt files while evading most third‑party AV. The report includes two file hashes as IoCs and notes that WatchGuard sandboxing and TDR modules detected or blocked the threat only under certain conditions, highlighting the need for layered defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.