News Room
16
Share
MedusaLocker Ransomware Escalates Activity with Targeted Attack on Bulgarian Organization Abv
highThreat Intelligence

MedusaLocker Ransomware Escalates Activity with Targeted Attack on Bulgarian Organization Abv

The MedusaLocker ransomware group has claimed responsibility for a recent breach of the Bulgarian organization Abv, resulting in the exfiltration of hundreds of sensitive emails.

27 September 2026Last updated 27 September 20263 min readDeXpose
E
Encrygma AI Cyber Weapons Advisory Services :We sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Threat Intelligence
Severity:
High
Actor Type:
Ransomware Group
Geography:
Bulgaria
Confidence:
Confirmed
Source:
DeXpose
Read Time:
3 min

Executive Summary On September 23, 2026, the MedusaLocker ransomware group successfully compromised the infrastructure of the Bulgarian organization Abv (abv.bg). This incident, reported on September 24, 2026, involved the unauthorized extraction of 583 internal emails. The attack highlights the persistent threat posed by established ransomware syndicates as they continue to target regional entities across Europe. ## Threat Analysis MedusaLocker remains a highly active threat actor, consistently employing double-extortion tactics to pressure victims into paying ransom demands. By exfiltrating sensitive data before encryption, the group ensures leverage even if the victim possesses robust backup solutions. This specific attack on Abv demonstrates the group's focus on regional organizations that may have gaps in their perimeter security or email server configurations. ## Technical Details The attack vector involved the exploitation of vulnerabilities within the target's email server infrastructure. Once initial access was established, the threat actors moved laterally to identify and exfiltrate high-value communications. The exfiltrated data, consisting of 583 emails, serves as the primary leverage for the group's extortion demands. MedusaLocker typically utilizes custom encryption routines and automated scripts to maximize the speed of file locking across Windows-based environments, often disabling shadow copies to prevent easy recovery. ## Attribution Assessment Attribution is assigned to the MedusaLocker group based on their public claim of responsibility and the observed tactics, techniques, and procedures (TTPs) consistent with their historical operations. MedusaLocker is known for its aggressive pursuit of data exfiltration and its use of dark web leak sites to publish stolen information when ransom demands are not met. ## Implications The breach of Abv underscores the ongoing risk to organizations that manage large volumes of user communications. The potential for these emails to contain sensitive personal or proprietary information poses a significant privacy risk to the organization's users and stakeholders. Furthermore, the incident serves as a reminder that regional organizations are not immune to the global ransomware epidemic. ## Recommendations Organizations are advised to implement strict email security protocols, including multi-factor authentication (MFA) for all administrative and user accounts. Regular patching of server-side software and the implementation of robust network segmentation are critical to limiting the impact of a potential breach. Additionally, organizations should maintain offline, immutable backups to ensure business continuity in the event of a successful ransomware deployment.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo