medusalocker
Medusa is a DDoS bot written in .NET 2.0. In its current incarnation its C&C protocol is based on HTTP, while its predecessor made use of IRC.
Medusalocker is a .NET 2.0-based crimeware DDoS bot using HTTP C2 for volumetric attacks.
Medusalocker is a crimeware DDoS bot developed in .NET 2.0, primarily focused on volumetric attacks. It targets multiple sectors including Technology, Manufacturing, Government & Defense, and Healthcare across countries like Germany, France, Canada, and the UAE. Key TTPs involve DDoS attacks via an HTTP-based C2 protocol, representing a shift from the earlier IRC-based predecessor. Defenders should monitor for anomalous HTTP traffic and potential botnet aggregation, especially in .NET environments, to detect this activity early.
Medusa is a DDoS bot written in .NET 2.0. In its current incarnation its C&C protocol is based on HTTP, while its predecessor made use of IRC.
The Medusalocker bot is written in .NET 2.0.
The current C2 protocol of Medusalocker is based on HTTP, while its predecessor used IRC.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.