MedusaLocker Ransomware Will Bypass Most Antivirus Software
ID: ff50e709-1c95-5d6d-baf0-71406426924f
STIX ID: report--ff50e709-1c95-5d6d-baf0-71406426924f
Feed Name: WatchGuard Secplicity Blog
A MedusaLocker ransomware variant (or copycat) was observed using a malicious batch file to disable Windows Defender in Safe Mode (deleting the SafeBoot WinDefend registry key), install itself as a service named "backupvt" configured for Safe Mode Minimal, force a reboot into Safe Mode, and then run to encrypt files while evading most third‑party AV. The report includes two file hashes as IoCs and notes that WatchGuard sandboxing and TDR modules detected or blocked the threat only under certain conditions, highlighting the need for layered defenses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
