LockerGoga is a Windows ransomware family used in targeted attacks against large enterprises, including industrial, manufacturing, transportation, chemical, and technology organizations in Europe and North America. It encrypts files outside core Windows directories using per-file AES encryption with RSA-protected key material, then leaves ransom instructions directing victims to contact the operators. Some variants encrypt broadly enough to affect boot-related files, potentially rendering a system unbootable after restart. The malware uses a master-and-worker process model to parallelize encryption and prioritizes business-relevant documents and data before encrypting additional files. Observed variants also log off users, change administrator-account passwords, disable network interfaces, wipe free disk space, clear event logs, and remove their own executable, substantially impeding recovery and forensic investigation. LockerGoga has been linked to criminal operations that obtained access to corporate environments, moved laterally, and deployed ransomware after extended network reconnaissance. A Swiss court found a Ukrainian national to have been the lead developer of LockerGoga, MegaCortex, and Nefilim; U.S. authorities have separately charged Volodymyr Tymoshchuk as an alleged administrator of those operations. A free decryptor was released in 2022 for certain historical LockerGoga cases.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The court found the unnamed Ukrainian man to be the lead developer of the LockerGoga, MegaCortex, and Nefilim ransomware families. Bitdefender released a free LockerGoga decryptor in 2022.
Les attaques ont utilisé trois familles de ransomware : LockerGoga, MegaCortex, Nefilim.
Pick-Six: Intercepting a FIN6 Intrusion, an Actor Recently Tied to Ryuk and LockerGoga Ransomware.
L’ANSSI a observé depuis maintenant plusieurs mois des campagnes d’attaques dans lesquelles des rançongiciels nommés « LockerGoga » et « Ryuk » sont déposés sur les systèmes d’information des victimes.
"From mid-2018... FIN6 or affiliated parties were distributing the Ryuk and LockerGoga ransomware"
29 distinct techniques documented for this family, organized by ATT&CK tactic.
La section « TTPs et IOCs détectés » associe explicitement T1078 — Valid Accounts aux attaques attribuées à Oleksandr Ieremenko.
Talos has also observed versions of the LockerGoga ransomware that attempt to clear the Windows Event Logs
その後、自身の本体である実行ファイルを3秒後に削除するバッチファイルを作成して実行します。つまり、LockerGogaは自動起動エントリーなどを作成せず、一度動作するとその一回切りで自己消去する
Le suspect est présenté comme le principal développeur des rançongiciels Lockergoga, Megacortex et Nefilim; Stadler Rail a été sommée de payer une rançon en bitcoin.
TTPs et IOCs détectés # TTP # T1486 — Data Encrypted for Impact (Impact) T1489 — Service Stop (Impact)
Windows標準ツールである「cipher.exe」を利用して、全てのドライブの空き領域を消去します。これには、フォレンジックによるファイルの復元を困難にさせる目的があると考えられます。
LockerGogaはOS標準ツールである「netsh.exe」を利用して、端末に存在する全てのネットワークインターフェイスを無効にします。
全ての対象ファイルの暗号化が終わると、LockerGoga(マスター)は、OS標準ツールの「logoff.exe」を利用して、自身が動作しているユーザーセッション以外の全てのセッションのログオフを試みます。
標準ユーザーを除く全ての管理者アカウントのユーザーのパスワードを強制的に「HuHuHUHoHo283283@dJD」という共通の文字列に設定します
153 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
70 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware family used to blackmail organizations worldwide by encrypting files; its source code was allegedly developed by the convicted individual. A free decryptor was released in 2022.
Ransomware family mentioned only in passing in relation to an unrelated Swiss criminal sentence.
Ransomware allegedly developed by the convicted suspect; it was used in attacks including those targeting French organizations, and a decryptor was subsequently published following the investigation.
Ransomware family that the convicted developer was found to have developed; the article does not specify its technical functionality beyond ransomware activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.