Ransomware Group intelligence

Medusalocker

Inactive

Track Medusalocker with 52 published victims and 4 known leak locations in a single intelligence view.

Victims 52 Known published victims in this dataset
First discovered 2022-11-15 Earliest victim discovery date
Last discovered 2025-11-18 Latest victim discovery date
Inactive since 158 days Days since the latest known victim
Top country United States 4 victims
Known locations 4 Leak or negotiation infrastructure tracked

Overview

Medusalocker is tracked by Breach House as a ransomware group with 52 published victims.

United States is currently the most targeted country in this dataset.

4 known leak locations are currently associated with this group.

Top Countries

Interactive distribution based on the currently visible victims list.

Top Countries
Distribution

    Known Leak Locations (4)

    Label Type Availability Links
    Leak location 1 Onion service Unknown qd7pcafncosqfqu3ha6fcx4h6sr7tzwagzpcdcnytiw3b6varaeqv5yd.onion
    Leak location 2 Onion service Unknown z6wkgghtoawog5noty5nxulmmt2zs7c3yvwr22v4czbffdoly2kl4uad.onion
    Leak location 3 Web location Unknown 95.143.191.148:3000
    Leak location 4 Onion service Unknown medusaxko7jxtrojdkxo66j7ck4q5tgktf7uqsqyfry4ebnxlcbkccyd.onion

    Top Activity Sectors

    No sector intelligence available.

    Research Sources

    No external research sources linked yet.

    Victims (52)

    Search, filter and paginate the victim timeline for Medusalocker.

    Type Target Discovered Country Business Category Intel Link
    Ransomware dulay.ca id23957 View details Canada Communication / Marketing
    Ransomware usenergy id22359 View details United States Energy
    Ransomware Looking for pentesters id21590 View details Other
    Ransomware UnigazJordan id20337 View details Jordan Other
    Ransomware Mulia Raya id20305 View details Indonesia Other
    Ransomware Curtain Bluff id18702 View details Antigua and Barbuda Finance / Legal / Insurance
    Ransomware Inversiones Clinica Del Meta SA id18092 View details Colombia Healthcare / Pharma
    Ransomware MICRO MANUFACTRING id17454 View details Communication / Marketing
    Ransomware bendixengineering id16545 View details United States Manufacturing / Engineering
    Ransomware SILKNET COMPANY id15662 View details United States Finance / Legal / Insurance
    Ransomware Protected: HIDE NAME id12401 View details Communication / Marketing
    Ransomware SHAMASS.ORG id12239 View details United States Communication / Marketing
    Ransomware Protected: HIDE NAME SELL DATA SOON id12147 View details Communication / Marketing
    Ransomware Protected: Name is hidden id9793 View details Communication / Marketing
    Ransomware skalar.com id9786 View details Communication / Marketing
    Ransomware Ada-Borup-West School id9182 View details Education
    Ransomware wellons.org id9181 View details Communication / Marketing
    Ransomware Confidential files id8933 View details Finance / Legal / Insurance
    Ransomware INSULCANA CONTRACTING LTD id8032 View details Communication / Marketing
    Ransomware Protected: INSULCANA CONTRACTING LTD id7950 View details Communication / Marketing
    Ransomware Protected: Hidden name id7335 View details Communication / Marketing
    Ransomware Hoosier Equipment company id7114 View details Communication / Marketing
    Ransomware Ucamco Belgium id7100 View details Finance / Legal / Insurance
    Ransomware reutlingen.ihk.de id7011 View details Germany Communication / Marketing
    Ransomware Hausamman company id7010 View details Communication / Marketing
    Ransomware kafflogistic.hu id7009 View details Hungary Communication / Marketing
    Ransomware SELL DATA(qtox) id7008 View details Communication / Marketing
    Ransomware Jalux Americas, Inc. id6855 View details Communication / Marketing
    Ransomware arborsct.com id6854 View details Finance / Legal / Insurance
    Ransomware Salmon Software id6720 View details IT
    Ransomware LETAPE JEUNES id6719 View details Communication / Marketing
    Ransomware bsw-architects.com id6080 View details Communication / Marketing
    Ransomware DGLEGAL id4602 View details Finance / Legal / Insurance
    Ransomware emscrm id4601 View details Other
    Ransomware MIDAS Company id4600 View details Services
    Ransomware AURIS KONINKLIJKE AURIS GROEP id4599 View details Other
    Ransomware fidelityunited.ae id4598 View details United Arab Emirates Other
    Ransomware goldcreekfoods id4597 View details Agriculture / Food
    Ransomware exheat.com id4596 View details Other
    Ransomware hwrpc.com id4595 View details Other
    Ransomware tristatefabricators_inc id4593 View details Public Sector
    Ransomware atlantisholidays id4592 View details Other
    Ransomware archimages inc id4591 View details Services
    Ransomware ALTlTUDE AEROSPACE INC id4590 View details Services
    Ransomware Fonderia Boccacci id4589 View details Other
    Ransomware Zelena Laguna Hotel id4588 View details Hospitality / Food & Beverage / Tourism
    Ransomware LEGAZPIBANK id4587 View details Finance / Legal / Insurance
    Ransomware MCCLEAN16 company id4586 View details Services
    Ransomware lawtrade company id4585 View details Finance / Legal / Insurance
    Ransomware Autosoft company id4584 View details Services
    Ransomware BIOPLAN id4583 View details Other
    Ransomware Dyatech company id4582 View details IT