MedusaLocker Ransomware

MedusaLocker Ransomware Description

There has been a brand new file-locking Trojan, which was spotted by malware researchers recently. It was given the name MedusaLocker Ransomware. Unlike most newly discovered ransomware threats, this data-encrypting Trojan appears to be a project built from square one as it does not belong to any of the known ransomware families. So far, cybersecurity experts have not been able to create a decryption tool and release it publicly.


It is not clear what propagation kind is being utilized in the spreading of the MedusaLocker ransomware. Some believe that mass spam email campaigns may be responsible for the propagation of this threat. Bogus application updates and fake pirated variants of popular software also is a common technique for spreading malware of this class.

The Two Variants of the MedusaLocker Ransomware

Malware researchers have spotted two variants of the MedusaLocker ransomware. The first copy of this threat appends a '.skynet' extension at the end of the filename of all the newly encrypted files. This variant of the MedusaLocker ransomware also drops a ransom note named 'Readme.html.' There are two email addresses provided in the ransom message - ‘' and ‘' The second copy of the MedusaLocker ransomware adds a different extension to the affected files - '.encrypted.' The name of the ransom note also is different, as this one is called 'HOW_TO_RECOVER_DATA.html.' Again two email addresses have been given out, and as you may have guessed, they are not the same ones as the ones provided in the first note - ‘' and ‘'

The message of the notes is the same apart from the differences we already outlined. There is no mention of a specific ransom fee in either one of the notes, but the attackers mention that the fee should be paid in the shape of Bitcoin.

We advise you against contacting cybercriminals as these are not individuals you can trust. It is likely they will promise you the decryption key if you pay up, but more often than not, these are just empty words. Make sure you download and install a reputable anti-virus application that will aid you in removing the MedusaLocker ransomware from your system.

Do You Suspect Your PC May Be Infected with MedusaLocker Ransomware & Other Threats? Scan Your PC with SpyHunter

SpyHunter is a powerful malware remediation and protection tool designed to help provide PC users with in-depth system security analysis, detection and removal of a wide range of threats like MedusaLocker Ransomware as well as a one-on-one tech support service. Download SpyHunter's FREE Malware Remover
Note: SpyHunter's scanner is only for malware detection. If SpyHunter detects malware on your PC, you will need to purchase SpyHunter's malware removal tool to remove the malware threats. Read more on SpyHunter. Free Remover allows you to run a one-off scan and receive, subject to a 48-hour waiting period, one remediation and removal. Free Remover subject to promotional details and Special Promotion Terms. To understand our policies, please also review our EULA, Privacy Policy and Threat Assessment Criteria. If you no longer wish to have SpyHunter installed on your computer, follow these steps to uninstall SpyHunter.

Security Doesn't Let You Download SpyHunter or Access the Internet?

Solutions: Your computer may have malware hiding in memory that prevents any program, including SpyHunter, from executing on your computer. Follow to download SpyHunter and gain access to the Internet:
  • Use an alternative browser. Malware may disable your browser. If you're using IE, for example, and having problems downloading SpyHunter, you should open Firefox, Chrome or Safari browser instead.
  • Use a removable media. Download SpyHunter on another clean computer, burn it to a USB flash drive, DVD/CD, or any preferred removable media, then install it on your infected computer and run SpyHunter's malware scanner.
  • Start Windows in Safe Mode. If you can not access your Window's desktop, reboot your computer in "Safe Mode with Networking" and install SpyHunter in Safe Mode.
  • IE Users: Disable proxy server for Internet Explorer to browse the web with Internet Explorer or update your anti-spyware program. Malware modifies your Windows settings to use a proxy server to prevent you from browsing the web with IE.
If you still can't install SpyHunter? View other possible causes of installation issues.

Leave a Reply

Please DO NOT use this comment system for support or billing questions. For SpyHunter technical support requests, please contact our technical support team directly by opening a customer support ticket via your SpyHunter. For billing issues, please refer to our "Billing Questions or Problems?" page. For general inquiries (complaints, legal, press, marketing, copyright), visit our "Inquiries and Feedback" page.