MalasLocker is a ransomware and extortion threat actor that emerged in early 2023 and became one of the more active double-extortion operations observed in the first half of that year. The group has been tracked alongside other newly active ransomware crews and was publicly identified as a newcomer in the 2023 ransomware landscape. MalasLocker has been associated with double extortion activity, combining data theft with coercive pressure on victims. It has also been described as using an unusual extortion narrative in which victims were asked to donate to charity rather than pay a conventional ransom demand. Despite that branding, the operation is categorized within the broader ransomware and extortion ecosystem. Victimology attributed to MalasLocker is geographically diverse. Available reporting indicates that North America and Western Europe were among the most affected regions in the broader campaign environment in which MalasLocker operated, and Russian-based victims accounted for a notable share of MalasLocker victims. Sector-level reporting tied to the same double-extortion wave indicates strong impact on professional, scientific, and technical services as well as manufacturing. MalasLocker is notable less for bespoke technical tradecraft publicly documented in detail than for its prominence among active extortion actors during the first half of 2023 and for its atypical public-facing ransom posture.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Newer double-extortion ransomware operation (emerged April 2023) noted for targeting some Russia-based companies and demanding charity donations instead of ransom in at least some cases.
Newly observed ransomware group monitored by NCC Group (no additional operational details provided).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.