VORANT. Threat Intelligence Research Sign in Create a free account

MedusaLocker lists ATCO Ltd as victim

elevated threat energy

Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.

Ransomware tracking site Ransomware.live logged ATCO Ltd as a victim claimed by the MedusaLocker ransomware group.

This entry is a victim listing from Ransomware.live, an aggregator that tracks claims made by ransomware groups on their leak sites. The record indicates that the MedusaLocker ransomware operation has listed ATCO Ltd as a victim. The article itself is sourced from a sponsored aggregator page and contains minimal technical detail beyond leak-site metadata: it references 10 third-party employee credentials and a leak screenshot, but provides no indication of compromised internal employees, compromised users, or exposed external attack surface counts.

No technical indicators of compromise, exploited vulnerabilities, malware samples, or TTPs are included in this listing. Defenders at ATCO Ltd or its supply chain/third parties should treat this as a notification of a claimed breach and pursue incident response, credential resets for any third-party accounts, and monitoring for data leaks, rather than acting on any technical detail, since none is provided here.

MedusaLocker is a known ransomware-as-a-service family that has been active since 2019, typically gaining initial access via exposed RDP, phishing, or vulnerability exploitation, followed by data exfiltration and encryption with double-extortion tactics. This specific listing does not describe the intrusion vector or timeline for the ATCO Ltd incident.

Mentioned in this report

Threat actors medusalocker
Malware MedusaLocker

Source reporting: https://www.ransomware.live/id/QVRDTyBMdGRAbWVkdXNhbG9ja2Vy

What this brief leaves out

This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.

It sits in a corpus of 11,126 reports from 154 sources, 2,670 of them written in the last seven days, and it grows through the day.

A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.

Create a free account   What it costs