SugarLocker is a Russia-linked ransomware gang associated with the Shtazi-IT operation. Russian law-enforcement actions identified and arrested alleged members of the group, and court proceedings tied one suspect, Aleksandr Gennadievich Ermakov, to co-writing SugarLocker and selling it with an attached Tor-based control panel. The group has been described as a ransomware crew operating behind Shtazi-IT, a malware development and sales operation advertised on Russian-language cybercrime forums. Known associated aliases and handles linked in reporting to the broader operation include SHTAZI, shtaziIT, JimJones, GustaveDore, and GistaveDore. SugarLocker’s activity is consistent with financially motivated ransomware operations. Reported behavior includes developing malware intended to encrypt victims’ data and extort payment for decryption. The group’s known capabilities therefore include initial access in support of ransomware deployment, post-exploitation actions culminating in file encryption, defense evasion typical of criminal malware operations, and extortion through ransom demands. Available high-confidence reporting in this context does not establish a broader victimology by country or sector beyond commercial organizations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named ransomware crew linked in the article to Shtazi-IT and to Ermakov through forum handles and Russian criminal case material about co-writing and selling SugarLocker.
Local ransomware gang whose alleged members were arrested and prosecuted in Russia.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.