Description
Ako (a.k.a. MedusaLocker) is a ransomware family used by a ransomware as a service operation active since 2019. Its operators gain initial access through remote desktop services and phishing emails, disable security software, and encrypt files with a hybrid scheme that leaves a ransom note demanding payment. The group pressures victims through a leak site and has repeatedly targeted healthcare and small organizations that lack strong defenses.
Stats
- First seen
- May 2022
- Last seen
- October 2026
Alert name variants
| Alert Name |
|---|
| Android.Ransomware.Ako |
| Document-Word.Ransomware.Ako |
| Script-JS.Ransomware.Ako |
| Win32.Ransomware.Ako |