216.73.217.174

Windows Locker Ransomware Analysis

· Published 29/01/2025 08:27 · Modified 29/01/2025 13:32

Export JSON

Essential information

Published
29/01/2025 08:27
Modified
29/01/2025 13:32
Tags
2025-01-29 ransomware windows locker
Related entities
16 techniques (mitre), 1 malware

Description

A new strain called '' has been identified, targeting victims by encrypting files and appending the .winlocker extension. Upon infection, it drops a ransom note named Readme.txt with instructions for contacting the attacker. Written in .NET, this sophisticated malware modifies registry keys for persistence, deletes shadow copies, and disables system defenses. It employs AES encryption with a 256-bit key, creates autorun entries, replicates onto removable drives, and disables Windows Defender and Task Manager. The generates a unique identifier for infected systems, retrieves the local IP address, and includes personalized details in the ransom note. It also modifies the desktop background as part of its psychological impact.

External references