
highThreat Intelligence
MedusaLocker Ransomware Escalates Activity with Targeted Attack on Bulgarian Organization Abv
The MedusaLocker ransomware group has claimed responsibility for a recent breach of the Bulgarian organization Abv, resulting in the exfiltration of hundreds of sensitive emails.
27 September 2026Last updated 27 September 20263 min readDeXpose
E
Encrygma AI Cyber Weapons Advisory Services :We sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram
Executive Takeaway — TL;DR
- Category:
- Threat Intelligence
- Severity:
- High
- Actor Type:
- Ransomware Group
- Geography:
- Bulgaria
- Confidence:
- Confirmed
- Source:
- DeXpose
- Read Time:
- 3 min
Executive Summary On September 23, 2026, the MedusaLocker ransomware group successfully compromised the infrastructure of the Bulgarian organization Abv (abv.bg). This incident, reported on September 24, 2026, involved the unauthorized extraction of 583 internal emails. The attack highlights the persistent threat posed by established ransomware syndicates as they continue to target regional entities across Europe. ## Threat Analysis MedusaLocker remains a highly active threat actor, consistently employing double-extortion tactics to pressure victims into paying ransom demands. By exfiltrating sensitive data before encryption, the group ensures leverage even if the victim possesses robust backup solutions. This specific attack on Abv demonstrates the group's focus on regional organizations that may have gaps in their perimeter security or email server configurations. ## Technical Details The attack vector involved the exploitation of vulnerabilities within the target's email server infrastructure. Once initial access was established, the threat actors moved laterally to identify and exfiltrate high-value communications. The exfiltrated data, consisting of 583 emails, serves as the primary leverage for the group's extortion demands. MedusaLocker typically utilizes custom encryption routines and automated scripts to maximize the speed of file locking across Windows-based environments, often disabling shadow copies to prevent easy recovery. ## Attribution Assessment Attribution is assigned to the MedusaLocker group based on their public claim of responsibility and the observed tactics, techniques, and procedures (TTPs) consistent with their historical operations. MedusaLocker is known for its aggressive pursuit of data exfiltration and its use of dark web leak sites to publish stolen information when ransom demands are not met. ## Implications The breach of Abv underscores the ongoing risk to organizations that manage large volumes of user communications. The potential for these emails to contain sensitive personal or proprietary information poses a significant privacy risk to the organization's users and stakeholders. Furthermore, the incident serves as a reminder that regional organizations are not immune to the global ransomware epidemic. ## Recommendations Organizations are advised to implement strict email security protocols, including multi-factor authentication (MFA) for all administrative and user accounts. Regular patching of server-side software and the implementation of robust network segmentation are critical to limiting the impact of a potential breach. Additionally, organizations should maintain offline, immutable backups to ensure business continuity in the event of a successful ransomware deployment.
ENCRYGMA
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Share
Back to News RoomRelated Intelligence

Emperador Ransomware Group Escalates Operations with Targeted Attack on BAYMER
22 Sep 2026

Ransomware Surge: Over 1,000 Organizations Compromised in August 2026 Amidst Escalating Gang Conflicts
27 Sep 2026

Ransomware Surge Continues: Qilin and ShinyHunters Lead Global Extortion Campaigns
26 Sep 2026
