Mount Locker is a human-operated ransomware operation active since at least mid-2020 that conducts double-extortion attacks against corporate victims. The group steals data prior to encryption and pressures victims with ransom demands backed by threats to publish stolen information on a leak site. Reported demands have reached multimillion-dollar amounts, and the operation has also used coercive pressure beyond simple encryption, including threats to expose victim data publicly. Mount Locker has been associated with targeted intrusions into enterprise networks followed by manual deployment of ransomware. Reported intrusion activity includes unauthorized remote access using compromised credentials, use of Active Directory APIs and LDAP queries for network enumeration, and domain-aware operations. The malware has been observed encrypting selected file types, including tax-related files associated with TurboTax, indicating deliberate victim-impact tuning. Technical reporting describes Mount Locker using ChaCha20 for file encryption with an embedded RSA public key protecting the symmetric key, and using ransom-note and file-association mechanisms to direct victims into negotiation workflows. The operation maintains a leak site as part of its extortion model and is consistently described as stealing unencrypted files before encryption. Mount Locker has also been linked to broader criminal ecosystem relationships. Reporting has assessed that Prophet Spider likely acted as an access broker for Mount Locker in some intrusions. Separate investigations found a close operational relationship between Mount Locker and Astro Locker Team, including shared victims across leak sites, matching leak metadata, shared or overlapping infrastructure for leaked data, the same ransom note, and similar tradecraft. Astro Locker has been assessed as possibly a rebrand, affiliate, or expansion path for Mount Locker, though the exact relationship remains unresolved. Mount Locker has also been discussed as having some affiliation with Ragnar Locker, but without confirmed overlap in malware or core TTPs. Overall, Mount Locker fits the model of a financially motivated enterprise ransomware actor focused on post-compromise operations, data theft, encryption, and extortion against organizational networks.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
25 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware group involved in the incident; evidence from TTPs, files, ransom note, and leak-site overlap suggests a close relationship with Astro Locker, potentially as rebranding or an affiliate/RaaS arrangement.
Ransomware operator(s) likely receiving brokered access from Prophet Spider to deploy ransomware in compromised environments.
Referenced as a ransomware operation that previously used Windows Active Directory APIs to perform LDAP queries.
Older ransomware group linked to Astro Locker; the content suggests Astro Locker may be a rebranding connected to the Mount Locker operation. Past Mount Locker intrusions reportedly used compromised credentials to access target environments over RDP.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.