Medusalocker

Active
Medusa is a DDoS bot written in .NET 2.0. In its current incarnation its C&C protocol is based on HTTP, while its predecessor made use of IRC.
67 Victims
Nov 2, 2021 First Discovered
May 5, 2026 Last Discovered
43 Days Inactive
25% Infostealer
1/5 Sites Online
Top Countries
US 9
GB 3
BR 2
MY 1
AU 1
IL 1
IT 1
FR 1
CR 1
CA 1
Top Sectors
Business Services 11
Manufacturing 8
Technology 8
Education 4
Construction 3
Agriculture and Food Production 3
Hospitality and Tourism 3
Financial Services 3
Consumer Services 2
Transportation/Logistics 2
Known Locations (5)
File Manager
t33zoj4qwv455fog7qnb2azi5xcdxkixughmmduzbw2rtdgryqfbh6id.onion
Human Verify
medusaxko7jxtrojdkxo66j7ck4q5tgktf7uqsqyfry4ebnxlcbkccyd.onion
qd7pcafncosqfqu3ha6fcx4h6sr7tzwagzpcdcnytiw3b6varaeqv5yd.onion
Medusa Chat
95.143.191.148:3000
Ransomware blog – We will not give ourselves a name. Just watch out for the leakage of your data:)
z6wkgghtoawog5noty5nxulmmt2zs7c3yvwr22v4czbffdoly2kl4uad.onion
Tools Used
CredentialTheft
Invoke-TheHash, Mimikatz
DefenseEvasion
HRSword, PCHunter, ProcessHacker
DiscoveryEnum
Advanced IP Scanner, Advanced Port Scanner, SoftPerfect NetScan
LOLBAS
PsExec
Offsec
Impacket
RMM-Tools
Remote Desktop Plus (RDP+)
Intelligence
Victims (67)
Elken Sdn Bhd
MY Consumer Services Discovered: May 5, 2026 · Attack est.: May 5, 2026
MLM / health & beauty products company. ~16k emails extracted.
Bandeirante Supermercados
BR Consumer Services Discovered: May 5, 2026 · Attack est.: May 5, 2026
Brazilian supermarket chain.
Strategic Imports
AU Business Services Discovered: May 5, 2026 · Attack est.: May 5, 2026
Australian auto parts/batteries importer. Brands: Strategic Imports, Auto Parts Now, Discount Batteries Now. User: bstuart (Brad Stuart). QNAP NAS (CACHEDEV1_DATA).
Magnolia (Israel)
IL Discovered: May 5, 2026 · Attack est.: May 5, 2026
Israeli jewelry company. Silver & accessories, participates in Vicenza jewelry fair (2025/2026). Sells via buyme.co.il gift cards. ~38k files, invoices in Hebrew (SI/IN/OV prefix).
Atencio Engineering
US Construction Discovered: May 5, 2026 · Attack est.: May 5, 2026
Civil engineering & land surveying firm. Services: site plans, boundary surveys, OWTS (septic) design, fire line design, elevation certificates, flood plain analysis. Clients in Las Animas County, Pueblo County, Florence...
SIT Group / Robusta
IT Business Services Discovered: May 5, 2026 · Attack est.: May 5, 2026
Italian company SIT Group (sitgroup.it) and Bulgarian Robusta (robusta.bg). Also abv.bg emails.
Desert Christian Schools (DCS)
US Education Discovered: May 5, 2026 · Attack est.: May 5, 2026
K-12 Christian school affiliated with First Baptist Church of Lancaster, CA. ADP payroll, DCFS childcare program, City of Lancaster Water Safety program. Financial docs: P&L, Balance Sheet, Trial Balance, 1099s....
CourtSmart
US Business Services Discovered: May 5, 2026 · Attack est.: May 5, 2026
Court technology company. Domain courtsmart.com / COURTSMART2. Dev server: dev-rich20.courtsmart.com. Connections to JIS.org, nashville.org.
Hathcock (Personal)
Discovered: May 5, 2026 · Attack est.: May 5, 2026
Personal comprehensive reports. Individuals: Noel Ray Hathcock, Trinity John Hathcock.
ActionAid / TACOSA
GB Public Sector Discovered: May 5, 2026 · Attack est.: May 5, 2026
NGO sector. Domains: actionaid.org, tacosa.org.za, immigration.go.tz.
Palmers Relocations
GB Transportation/Logistics Discovered: May 5, 2026 · Attack est.: May 5, 2026
Australian international removals & relocation company. FIDI accredited, ISO 9001:2015 certified. Services: household moves, storage, customs, immigration (IMMI/VEVO). Operates Melbourne area (Pascoe Vale, Dandenong, Caulfield).
Académie de Montpellier / CSJM
FR Education Discovered: May 5, 2026 · Attack est.: May 5, 2026
French public school network. Domain CSJM.BEZIERS, part of Académie de Montpellier (ac-montpellier.fr). Occitanie region (laregion.fr). Teacher and admin staff credentials.
Colegio María Inmaculada (CMI)
CR Education Discovered: May 5, 2026 · Attack est.: May 5, 2026
Catholic school in Moravia, Costa Rica. Domain cmi.local / mariainmaculada.ed.cr. Servers: CMI-DC01, CMI-APP, CMI-HTTP2, main-server1/2.
CEAGESP / Netfeirasp
BR Agriculture and Food Production Discovered: May 5, 2026 · Attack est.: May 5, 2026
Brazilian produce wholesale market network. Domain netfeirasp.ceagesp (CEAGESP). Also demarchibrasil.com.br accounts.
Raycolighting
GB Manufacturing Discovered: May 5, 2026 · Attack est.: May 5, 2026
Organization with 2 emails extracted. Domain: raycolighting.com
dulay.ca
CA Technology Discovered: Nov 17, 2025 · Attack est.: Nov 17, 2025
Price-$40000 (sale in one hand there are options for making a profit from these files will be included in the deal) 500Gb
Trimble Inc / Gerrard Inc
US Technology Discovered: May 5, 2026 · Attack est.: Nov 7, 2025
Technology company Trimble (trimble.com) and Gerrard Inc (gerrardinc.com). ~18 Trimble email addresses.
usenergy
US Energy Discovered: Sep 14, 2025 · Attack est.: Sep 14, 2025
Price-$120000 (sale in one hand there are options for making a profit from these files will be included in the deal)
UnigazJordan
JO Energy Discovered: May 30, 2025 · Attack est.: May 30, 2025
www.unigaz.net $690.6 Million The list of files is available at the link https://dropmefiles.com/9HGAJ
Mulia Raya
ID Agriculture and Food Production Discovered: May 29, 2025 · Attack est.: May 29, 2025
www.muliaraya.co.id $34.8 Million The list of files is available at the link https://dropmefiles.com/lAZQo
Curtain Bluff
AG Hospitality and Tourism Discovered: Mar 25, 2025 · Attack est.: Mar 25, 2025
www.curtainbluff.com Curtain Bluff files Vacationer information (personal data), audit information (including past years), bank activity (statements with all transactions), internal organization documentation (even the menu) and other documents.There are also...
Inversiones Clinica Del Meta SA
CO Healthcare Discovered: Feb 28, 2025 · Attack est.: Feb 28, 2025
www.clinicameta.co Description employee information – patient information – agreements – password data – appointment information Sold with 1-day access Price-$100000 (sale in one hand there are options for making a...
MICRO MANUFACTRING
US Manufacturing Discovered: Feb 11, 2025 · Attack est.: Feb 4, 2025
Micro Manufacturing Inc. Descriptionemployee information – agreement – customer email(.xls)-.msg outlook files. password data\\ Sold with 1-day access Price-$120000 (sale in one hand there are options for making a profit...
bendixengineering
US Manufacturing Discovered: Jan 9, 2025 · Attack est.: Dec 27, 2024
Descriptionemployee information – agreement – customer email(.xls)-.msg outlook files Data-2016-2024 years Price-$50000 (sale in one hand there are options for making a profit from these files will be included in...
SILKNET COMPANY
US Business Services Discovered: Nov 26, 2024 · Attack est.: Nov 26, 2024
URL:https://silknet.com https://geocell.ge/ On sale:Company email base(about 1tb)Customer dataCompany audit for 2023\24and more than 3tb of data. Price-$800000 There are a lot of corporate data, passports and other information.
Protected: HIDE NAME
Discovered: May 8, 2024 · Attack est.: May 8, 2024
There is no excerpt because this is a protected post.
Protected: HIDE NAME SELL DATA SOON
Technology Discovered: Apr 25, 2024 · Attack est.: Apr 25, 2024
There is no excerpt because this is a protected post.
SHAMASS.ORG
US Discovered: May 2, 2024 · Attack est.: Apr 21, 2024
Descriptionemployee information – agreement – customer email(.xls)-.msg outlook files Price-$50000 (sale in one hand there are options for making a profit from these files will be included in the deal)
Protected: Name is hidden
Discovered: Nov 29, 2023 · Attack est.: Nov 29, 2023
There is no excerpt because this is a protected post.
skalar.com
Discovered: Nov 29, 2023 · Attack est.: Nov 29, 2023
There is no excerpt because this is a protected post.
wellons.org
Discovered: Oct 23, 2023 · Attack est.: Oct 23, 2023
Descriptionemployee information – agreement – customer email(.xls)- pst files 15+GB all outlook message 2006-2023 year Price: 55000$
Ada-Borup-West School
Education Discovered: Oct 23, 2023 · Attack est.: Oct 23, 2023
Descriptionemployee information – student information – all contracts Price: 35000$
Confidential files
Financial Services Discovered: Oct 2, 2023 · Attack est.: Oct 2, 2023
A large number of documents of large companies are available for sale Revenue-$10-$70kk Financial documents, client cases, passports, tax evasion and many other documents are in closed sale, please contact...
INSULCANA CONTRACTING LTD
Construction Discovered: Aug 3, 2023 · Attack est.: Jul 27, 2023
Descriptionemployee information – agreement – customer email(.xls)- passport all canada and other documents Price: 35000$
Protected: INSULCANA CONTRACTING LTD
Construction Discovered: Jul 27, 2023 · Attack est.: Jul 27, 2023
There is no excerpt because this is a protected post.
Protected: Hidden name
Discovered: Jul 17, 2023 · Attack est.: Jul 17, 2023
There is no excerpt because this is a protected post.
Hoosier Equipment company
Manufacturing Discovered: Jul 4, 2023 · Attack est.: Jul 4, 2023
DescriptionClient Case – agreement – email(.msg)- and other documents Price: 60000$
Ucamco Belgium
Technology Discovered: Jul 2, 2023 · Attack est.: Jul 2, 2023
DescriptionClient Case – customers email-Audit information-There is also access to email for newsletters on behalf of the company PRICE-$80000
SELL DATA(qtox)
Discovered: Jun 23, 2023 · Attack est.: Jun 16, 2023
Available for sale: to buy please contact qtox price negotiable qtox-E9CD65687463F67F64937E961DD723DC82C79CB548375AAE8AA4A0698D356C5E7E157B22E8CD
kafflogistic.hu
HU Transportation/Logistics Discovered: Jun 23, 2023 · Attack est.: Jun 16, 2023
DescriptionClient Case – agreement – email(outlook files)- contracts – and other documents PRICE-$50000
Hausamman company
Business Services Discovered: Jun 23, 2023 · Attack est.: Jun 16, 2023
DescriptionClient Case – customers email-documents PRICE-$20000
reutlingen.ihk.de
DE Business Services Discovered: Jun 23, 2023 · Attack est.: Jun 16, 2023
DescriptionClient Case – agreement – email(.msg)- contracts – and other documents PRICE-$80000
arborsct.com
Business Services Discovered: Jun 14, 2023 · Attack est.: Jun 14, 2023
DescriptionClient Case – agreement – email(.msg)- and other documents Price: 60000$ One copy will be sold, confidential informationThe company did not take care of the data leak, and therefore we...
LETAPE JEUNES
Discovered: Jun 3, 2023 · Attack est.: Jun 2, 2023
DescriptionClient Case – agreement – email(.msg)- contracts – and other documents(passports) PRICE-$40000
bsw-architects.com
Business Services Discovered: Apr 10, 2023 · Attack est.: Apr 10, 2023
DescriptionClient Case – agreement – email(.msg)- contracts – and other documents PRICE-$80000 There are many projects, agreements and contracts that can be sold separately
DGLEGAL
Business Services Discovered: Nov 15, 2022 · Attack est.: Nov 15, 2022
emscrm
Technology Discovered: Nov 15, 2022 · Attack est.: Nov 15, 2022
MIDAS Company
Discovered: Nov 15, 2022 · Attack est.: Nov 15, 2022
AURIS KONINKLIJKE AURIS GROEP
Discovered: Nov 15, 2022 · Attack est.: Nov 15, 2022
fidelityunited.ae
AE Financial Services Discovered: Nov 15, 2022 · Attack est.: Nov 15, 2022
goldcreekfoods
Agriculture and Food Production Discovered: Nov 15, 2022 · Attack est.: Nov 15, 2022
exheat.com
Manufacturing Discovered: Nov 15, 2022 · Attack est.: Nov 15, 2022
hwrpc.com
Discovered: Nov 15, 2022 · Attack est.: Nov 15, 2022
tristatefabricators_inc
Manufacturing Discovered: Nov 15, 2022 · Attack est.: Nov 15, 2022
atlantisholidays
Hospitality and Tourism Discovered: Nov 15, 2022 · Attack est.: Nov 15, 2022
archimages inc
Discovered: Nov 15, 2022 · Attack est.: Nov 15, 2022
ALTlTUDE AEROSPACE INC
Manufacturing Discovered: Nov 15, 2022 · Attack est.: Nov 15, 2022
Fonderia Boccacci
Manufacturing Discovered: Nov 15, 2022 · Attack est.: Nov 15, 2022
Zelena Laguna Hotel
Hospitality and Tourism Discovered: Nov 15, 2022 · Attack est.: Nov 15, 2022
LEGAZPIBANK
Financial Services Discovered: Nov 15, 2022 · Attack est.: Nov 15, 2022
MCCLEAN16 company
Discovered: Nov 15, 2022 · Attack est.: Nov 15, 2022
lawtrade company
Business Services Discovered: Nov 15, 2022 · Attack est.: Nov 15, 2022
Autosoft company
Technology Discovered: Nov 15, 2022 · Attack est.: Nov 15, 2022
BIOPLAN
Healthcare Discovered: Nov 15, 2022 · Attack est.: Nov 15, 2022
Dyatech company
Technology Discovered: Nov 15, 2022 · Attack est.: Nov 15, 2022
Salmon Software
Technology Discovered: Jun 3, 2023 · Attack est.: Jul 11, 2022
DescriptionClient Case – agreement – email(.msg)- passport- and other documents Price: 120000$ Three copies will be sold, confidential informationThe company failed to take care of the data leak and therefore...
Jalux Americas, Inc.
Business Services Discovered: Jun 14, 2023 · Attack est.: Nov 2, 2021
DescriptionClient Case – agreement – email(.msg) – and other documents Price: 160000$The company failed to take care of the data leak and therefore ,many contracts and other documents have been...