Threat Group Profile
medusalocker
● Active — last 30 days
Victim claims
31
First seen
May 2026
Last activity
16 Aug 2026
Tracked since
Nov 2022
Group overview
Medusa is a DDoS bot written in .NET 2.0. In its current incarnation its C&C protocol is based on HTTP, while its predecessor made use of IRC.
Preferred targets
Business Services · 5
Manufacturing · 4
Consumer Services · 3
Public Sector · 3
Education · 3
Technology · 2
Most targeted countries
DE · 4
GB · 4
BR · 3
FR · 3
US · 3
CA · 2
Tactics & techniques (MITRE ATT&CK)
Privilege Escalation
Parent PID Spoofing