Netskope Threat Labs

Ako

ATP Sandbox Adv. Heuristics

Ako (a.k.a. MedusaLocker) is a ransomware family used by a ransomware as a service operation active since 2019. Its operators gain initial access through remote desktop services and phishing emails, disable security software, and encrypt files with a hybrid scheme that leaves a ransom note demanding payment. The group pressures victims through a leak site and has repeatedly targeted healthcare and small organizations that lack strong defenses.

First seen
May 2022
Last seen
October 2026
Alert Name
Android.Ransomware.Ako
Document-Word.Ransomware.Ako
Script-JS.Ransomware.Ako
Win32.Ransomware.Ako