Astro Locker is a ransomware threat group associated with the Astro Locker Team and linked by multiple investigations to the older Mount Locker operation. The relationship has been assessed as a likely rebrand, close affiliate relationship, or an effort to expand Mount Locker into a more formal ransomware-as-a-service model, although the exact structure remains unresolved. Astro Locker conducts double-extortion operations, combining file encryption with theft of victim data and threats to publish that data on a dedicated leak site. The group has also used direct pressure tactics such as contacting victim organizations by email to force negotiations and impose short deadlines before publication. Operationally, Astro Locker has been observed deploying ransomware manually rather than as a fully autonomous worm-like payload. The malware has been executed through Rundll32 and supports command-line options consistent with operator-driven intrusions. Reported intrusion patterns tied to the related Mount Locker activity include unauthorized remote access via compromised credentials over RDP. Shared tradecraft between Astro Locker and Mount Locker includes service-based command execution, scheduled-task creation, and use of concealed staging locations, reinforcing the assessment of a material connection between the two operations. The Astro Locker ransomware payload has been described as a 64-bit DLL that creates a mutex derived from the victim system to avoid duplicate execution, logs its activity during runtime, terminates selected processes and services prior to encryption, and excludes certain files and directories to preserve system operability and attacker communication paths. For encryption it uses ChaCha20 with a randomly generated symmetric key that is then encrypted with an embedded RSA public key and appended to encrypted files. A notable usability feature is its modification of file-association behavior so that opening encrypted files presents the ransom instructions. After completing encryption, the malware removes itself through a self-deletion routine. Astro Locker is best characterized as a financially motivated ransomware and extortion actor. Known aliases in reporting include AstroLocker Team and Astro Locker Team. It is closely associated with Mount Locker and has also been discussed in relation to Ragnar Locker, though available evidence supports a clearer operational overlap with Mount Locker than with Ragnar Locker.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named ransomware brand closely tied to Mount Locker; shares victims, leak-site content, ransom notes, malware, and TTPs with Mount Locker, suggesting either a close affiliate relationship or rebranding effort.
Ransomware extortion group operating Astro Locker, using double extortion by encrypting files, demanding ransom, and threatening to publish stolen data on a leak site. The group also sends emails to victims to notify them of the compromise and pressure them to negotiate within 72 hours.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.