Astro Locker Team is a ransomware threat actor associated with the Astro Locker ransomware family and assessed to be materially connected to the older Mount Locker operation, possibly as a rebrand, affiliate, or early ransomware-as-a-service expansion. The group conducts double-extortion operations, combining file encryption with theft of sensitive data and threats to publish stolen material on a dedicated leak site. Victims have also been pressured through direct communications warning of imminent public release of exfiltrated data if negotiations do not begin. Operationally, Astro Locker Team appears to favor hands-on-keyboard deployment. Reported intrusion patterns linked to the broader Mount Locker/Astro Locker cluster include unauthorized remote access via compromised credentials over RDP. During execution, the ransomware is manually launched through Rundll32 as a 64-bit DLL and supports command-line options consistent with operator-driven use. Shared tradecraft observed across Astro Locker and Mount Locker includes service-based command execution, scheduled-task creation, and use of concealed file locations. The malware terminates selected processes and services prior to encryption, particularly software that could lock files such as database-related applications. It avoids encrypting certain files and directories needed for system stability or victim communication, creates a host-specific mutex to prevent duplicate execution, logs runtime activity, and self-deletes after encryption. Astro Locker uses ChaCha20 for file encryption and protects the generated symmetric key with an embedded RSA public key. A distinctive behavior is its modification of file-association settings so that opening an encrypted file launches the HTML ransom note, reinforcing the extortion workflow. Known aliases include Astro Locker and AstroLocker Team. The exact relationship between Astro Locker Team and Mount Locker remains unresolved, but overlap in ransomware tooling, ransom-note infrastructure, victim listings, and operational TTPs indicates a close connection.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named ransomware brand closely tied to Mount Locker; shares victims, leak-site content, ransom notes, malware, and TTPs with Mount Locker, suggesting either a close affiliate relationship or rebranding effort.
Ransomware extortion group operating Astro Locker, using double extortion by encrypting files, demanding ransom, and threatening to publish stolen data on a leak site. The group also sends emails to victims to notify them of the compromise and pressure them to negotiate within 72 hours.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.