Quick Summary
AllegedExecutive Summary
Qualisteel, a steel and metals manufacturer, was targeted by the MedusaLocker ransomware group, with the listing appearing on their leak site on August 27, 2026. SOCRadar’s Dark Web Monitoring service identified this incident. The company’s potential attractiveness to ransomware actors stems from the nature of its operations, which likely involve sensitive customer order data, production specifications, and supplier contracts, all of which are valuable for extortion. MedusaLocker has been actively targeting organizations across healthcare, manufacturing, and the public sector in the 60 days preceding this incident. Other companies listed in similar sectors, such as Bija Industrie, NSW Health, Hungry Lion, and Servifruit, have also been claimed by this group. Qualisteel’s inclusion within the manufacturing cohort aligns with MedusaLocker’s typical targeting patterns, where critical operational and commercial data can be leveraged for pressure.
Technical Analysis
A query of stealer-log data for the Qualisteel domain returned no records within the sampled dataset. It is crucial to note that this query covered a paginated slice of available data. Therefore, the absence of records does not definitively confirm that the organization is unaffected. Credentials could potentially exist under a sibling domain or be associated with personal email aliases not captured in this specific query. The lack of positive signals in this limited sample should be treated as just that—an absence of current evidence—and not as a confirmation of a clean security posture. The possibility remains that credentials may have been compromised and subsequently rotated before the data was indexed, or they may reside in datasets not included in this particular scan. The exposure of credentials, even if not immediately evident in this specific stealer-log sample, can provide a pathway for ransomware operators to gain initial access. Such compromised credentials, often harvested through infostealer malware, can be used to access corporate accounts, Microsoft 365, VPNs, or remote-access portals, potentially leading to further lateral movement and ransomware deployment. Continued monitoring for credentials and related indicators of compromise remains advisable.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.