ako logo

ako

2 incidentes 1 paises 0 sectores ransomware RU Ultimo: 2026-06-25
Aliases: Ako Doxware, MedusaReborn, Medusalocker
Ver en IntelTracker → APTTrail →
Ako is a financially motivated ransomware-as-a-service (RaaS) variant that emerged in September 2019, sometimes referred to as AKO Doxware or Medusa Reborn, though its creators have stated it is distinct from MedusaLocker. It operates on a model where core developers maintain the malware, and affiliates conduct attacks, with ransom payments typically split between them (55-60% to affiliates, the rest to developers). The group is assessed to be based in Russia, leveraging Russian infrastructure for its operations. What distinguishes Ako/MedusaLocker is its strategy of avoiding the encryption of executable files to ensure the compromised system remains functional for ransom payment. It also employs a hybrid encryption scheme using AES-256 and RSA-2048, and often reboots infected machines into safe mode to bypass security defenses.

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Victimas
1
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United States (1)

Paises objetivo (SOCRadar)

United Arab EmiratesAfghanistanAntigua and BarbudaAustraliaBelgiumBrazilCanadaSwitzerlandColombiaCosta Rica

Sectores objetivo (SOCRadar)

Construction of BuildingsFood ManufacturingOther Information ServicesSoftware PublishersReal EstateHospitalsEnterprises & HoldingAccommodationAir TransportationManufacturing

URLs nuevas detectadas en IntelTracker

github.com ransomware.anggipradana.com

Victimas (1)

Ransom Notes: ako (1 notes from ThreatLabz)18 Jun 2026
Report
ako - Ransom NotesEste grupo de ransomware tiene 1 notas de rescate documentadas en el repositorio ThreatLabz/ransomware_notes. Las notas de rescate s…