LockerGoga is a Windows ransomware family associated with targeted intrusions against large enterprises, including organizations in industrial and manufacturing sectors. Activity became prominent in early 2019 and has been linked to disruptive incidents affecting major corporations in the United States and Europe. The malware has been deployed in human-operated attacks in which adversaries first obtain network access, move laterally, and then manually launch ransomware across selected systems, often after extended dwell time. Reported intrusion methods associated with operations that deployed LockerGoga include phishing, exploitation of exposed services, SQL injection, stolen credentials, and remote administration tooling such as PsExec and RDP.
LockerGoga encrypts files across accessible drives while excluding the Windows directory, and some variants prioritize business-relevant document, database, source code, and similar file types before broader encryption. It uses per-file symmetric encryption with RSA-protected key material and appends metadata to encrypted files. Variants have dropped ransom notes that direct victims to contact the operators by email rather than through a payment portal. Multiple samples were observed signed with legitimate code-signing certificates, likely to reduce security scrutiny.
The malware is notable for disruptive post-encryption behavior beyond file locking. Observed variants have changed administrator account passwords, logged off users, disabled network interfaces, wiped free space with native Windows utilities, deleted their original launcher or self-deleted after execution, and in some cases cleared event logs. LockerGoga has also been observed encrypting boot-related files, which can leave systems unbootable after restart and has led some analysts to characterize certain incidents as partly destructive rather than purely extortion-driven.
Execution commonly requires administrative privileges. Some analyzed samples used a master-and-slave process model to coordinate encryption tasks through shared memory, while others were described as relatively unsophisticated in implementation despite causing severe operational impact. No reliable evidence indicates that LockerGoga self-propagates as a worm or depends on dedicated command-and-control infrastructure for encryption operations.
LockerGoga has been associated in reporting with criminal actors involved in big-game hunting ransomware operations, including overlaps in tradecraft with activity linked to Grim Spider and deployments by actors also tied to MegaCortex, Ryuk, and Dharma. Law-enforcement reporting has connected LockerGoga deployments to organized ransomware groups that combined initial access, persistence, lateral movement, and post-exploitation tooling before monetization.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Pick-Six: Intercepting a FIN6 Intrusion, an Actor Recently Tied to Ryuk and LockerGoga Ransomware.
L’ANSSI a observé depuis maintenant plusieurs mois des campagnes d’attaques dans lesquelles des rançongiciels nommés « LockerGoga » et « Ryuk » sont déposés sur les systèmes d’information des victimes.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
Some of these criminals were dealing with the penetration effort, using multiple mechanisms to compromise IT networks, including brute force attacks, SQL injections, stolen credentials and phishing emails with malicious attachments.
When interacting with the sample, Talos observed commands being executed to encrypt each individual file
Some of these criminals were dealing with the penetration effort, using multiple mechanisms to compromise IT networks, including brute force attacks, SQL injections, stolen credentials and phishing emails with malicious attachments.
標準ユーザーを除く全ての管理者アカウントのユーザーのパスワードを強制的に「HuHuHUHoHo283283@dJD」という共通の文字列に設定します
Cisco’s Talos group observed that some LockerGoga variants forcibly log victims off their devices. They are then unable to log back onto the device... in some cases the network interface on each system was disabled and the local user account passwords were changed.
攻撃者が遠隔から配布する場合はLockerGogaをPsExec等のツールや権限昇格に関わる脆弱性の利用など何らかの手口を利用して管理者権限で実行させる必要があります。
Talos has also observed versions of the LockerGoga ransomware that attempt to clear the Windows Event Logs
その後、自身の本体である実行ファイルを3秒後に削除するバッチファイルを作成して実行します。つまり、LockerGogaは自動起動エントリーなどを作成せず、一度動作するとその一回切りで自己消去する
Cisco’s Talos group observed that some LockerGoga variants forcibly log victims off their devices. They are then unable to log back onto the device... in some cases the network interface on each system was disabled and the local user account passwords were changed.
Some of these criminals were dealing with the penetration effort, using multiple mechanisms to compromise IT networks, including brute force attacks, SQL injections, stolen credentials and phishing emails with malicious attachments.
Cisco’s Talos group observed that some LockerGoga variants forcibly log victims off their devices. They are then unable to log back onto the device... in some cases the network interface on each system was disabled and the local user account passwords were changed.
どちらかといえば、PsExec等のツールやシステムサービスによる配布、脆弱性の利用等、なんらかの手段でユーザーの操作を介さずに管理者権限で実行させる感染手法を前提にして開発されているように見受けられます。
effectue différents rebonds via le protocole RDP (Remote Desktop) dans l’infrastructure ciblée
The criminals would then lay undetected in the compromised systems, sometimes for months, probing for more weaknesses in the IT networks before moving on to monetising the infection by deploying a ransomware. These cyber actors are known to have deployed LockerGoga, MegaCortex and Dharma ransomware, among others. | A ransom note was then presented to the victim, which demanded the victim pay the attackers in Bitcoin in exchange for decryption keys.
Windows標準ツールである「cipher.exe」を利用して、全てのドライブの空き領域を消去します。これには、フォレンジックによるファイルの復元を困難にさせる目的があると考えられます。
LockerGogaはOS標準ツールである「netsh.exe」を利用して、端末に存在する全てのネットワークインターフェイスを無効にします。
153 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
60 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as another ransomware family that used the Windows Restart Manager technique to deal with locked files.
LockerGoga is a ransomware family known for targeting large organizations and encrypting their data, often disrupting business operations.
Ransomware known for targeting large organizations and causing significant operational disruption by encrypting files and demanding ransom payments.
Ransomware strain known for high-profile attacks, notably the 2019 incident against Norsk Hydro, encrypting files and demanding ransom payments.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.