HexaLocker is a ransomware family and associated threat actor active since mid-2024. It is a Windows-focused, Golang-based operation that has advertised ransomware capabilities through Telegram and has been linked in reporting to the developer identity ZZART3XX and claimed associations with LAPSUS$. The actor has also been described as aligned at times with other ransomware operators, including DoubleFace, reflecting a fluid affiliate-style ecosystem rather than a stable, mature intrusion set. HexaLocker conducts ransomware and data-theft operations against Windows systems. Early observed variants encrypted files under user-profile directories, appended a dedicated ransomware extension, dropped a ransom note, and transmitted victim identification and encryption material to attacker-controlled infrastructure. Analysis of those variants indicated use of symmetric cryptography with Argon2ID-based key derivation and AES-GCM file encryption, alongside theft of selected victim files that were compressed and uploaded prior to or after encryption. Researchers also noted anti-analysis and anti-debugging features implemented through publicly available Golang modules, including checks for virtualization, debugger presence, suspicious execution environments, and other sandbox artifacts. A later variant, commonly referred to as HexaLocker V2, expanded the operation into a clearer double-extortion model. This version added persistence, stronger runtime string obfuscation, browser-data theft through the Skuld stealer, broader file collection for exfiltration, and subsequent file encryption. Reported functionality included copying itself into a user application-data location, establishing autorun persistence, decrypting operational strings at runtime, harvesting browser credentials and related browser-stored data, scanning local files for theft, exfiltrating stolen data, and then encrypting victim files with ChaCha20 after deriving keys with Argon2. Victim communications shifted from earlier methods to a unique personal hash model, with contact instructions via messaging platforms and web chat. HexaLocker should be characterized as a financially motivated ransomware actor using encryption plus data theft, with capabilities spanning initial malware execution on Windows, persistence, credential theft, exfiltration, defense evasion, and post-compromise monetization through extortion. Public reporting indicates the operation was briefly shut down in October 2024 and later revived in December 2024, suggesting ongoing development but also organizational instability.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named activity cluster around a ransomware project promoted within CyberVolk-aligned channels, featuring ongoing development of anti-analysis, EDR-killing, AMSI bypass, process injection, and UAC bypass capabilities before shutdown/sale announcements.
Ransomware operation developing and deploying HexaLocker V2, a Go-based Windows ransomware that adds persistence, downloads Skuld Stealer, steals browser data, exfiltrates victim files, and encrypts files using double extortion.
A newly advertised ransomware operation developing a Golang-based Windows ransomware with anti-analysis, file encryption, ransom note delivery, and post-encryption file exfiltration capabilities. The group stores decryption material on remote servers and is seeking partners to scale attacks.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.