LockerGoga is a ransomware operation associated with targeted intrusions against large organizations and is widely characterized as a big-game-hunting threat. It has been used in compromises affecting more than 250 companies in the United States and hundreds of additional organizations worldwide, including blue-chip companies, healthcare institutions, and large industrial firms. The operation caused major business disruption and multimillion-dollar losses through system damage and ransom demands. LockerGoga has been linked to Ukrainian administrator Volodymyr Viktorovich Tymoshchuk, also known as deadforz, Boba, msfv, and farnetwork, who was charged by U.S. authorities for his role in administering LockerGoga as well as MegaCortex and later Nefilim. The operation customized ransomware payloads for individual victims and used unique decryption keys per target. In cases where victims paid, operators provided decryption tools. Reported tradecraft associated with LockerGoga includes targeted enterprise compromise and lateral movement using PsExec. LockerGoga is commonly grouped with other human-operated ransomware families known for manual deployment inside victim networks after broader compromise activity. Law-enforcement action against the ecosystem led to the release of decryption keys for LockerGoga through the No More Ransom project in 2022.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
LockerGoga is associated with ransomware operations targeting companies, with activities managed by individuals such as Tymoshchuk.
LockerGoga is associated with ransomware attacks that breached hundreds of companies worldwide, resulting in millions of dollars in damages.
LockerGoga is a ransomware strain linked to actors involved in the Nefilim group, used in attacks against corporate networks for extortion.
LockerGoga is a ransomware group responsible for attacks on hundreds of organizations globally, causing significant operational disruption and financial losses. The group customized ransomware payloads for each victim and demanded ransom for decryption.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.