216.73.216.6

NailaoLocker Ransomware's 'Cheese'

· Published 21/07/2025 10:27 · Modified 21/07/2025 10:58

Export JSON

Essential information

Published
21/07/2025 10:27
Modified
21/07/2025 10:58
Tags
2025-07-21 aes-256-cbc dll side-loading multi-threaded nailaolocker ransomware sm2 cryptography windows
Related entities
3 observables, 9 techniques (mitre), 1 malware

Description

, a new variant targeting systems, uses encryption and uniquely incorporates with hard-coded keys. It employs for execution and uses I/O Completion Ports for file processing. The includes both encryption and decryption modes, with a built-in SM2 key pair. However, testing revealed the embedded private key fails to decrypt files properly, suggesting it may be a trap or an incomplete build. 's use of Chinese SM2 standards for key protection marks a departure from typical practices. While the decryption logic functions correctly with valid key material, the variant's true intent remains unclear.

External references