LukaLocker is a ransomware family associated with the threat actor tracked as Burning Scorpius, also referred to as Volcano Demon. Active since at least June 2024, it has been used to encrypt both Windows and Linux systems in enterprise environments. The malware is written in C++ and is designed to hinder analysis and detection through API obfuscation and dynamic API resolution.
LukaLocker is used in double-extortion operations in which data is exfiltrated before encryption and victims are subsequently pressured for payment. Reported intrusions involved the use of harvested administrative credentials to deploy the ransomware across Windows workstations and servers, and a Linux variant has also been observed on victim networks. The operator has been noted for aggressive extortion practices, including direct threatening phone calls to organizational leadership and IT personnel rather than relying solely on a public leak site.
On execution, LukaLocker can terminate a broad range of services and processes prior to encryption, including security tooling, backup and recovery software, databases, monitoring products, and remote administration tools, improving its ability to encrypt systems and impair response efforts. It also reportedly clears logs, complicating forensic reconstruction. The ransomware avoids encrypting selected system directories and certain file types in order to preserve system operability and ensure the ransom process can proceed.
For encryption, LukaLocker uses ChaCha8 for file data and derives key material using Curve25519-based ECDH. It supports both full and partial encryption modes, allowing only portions of files to be encrypted for speed and scale. Observed targeting indicates impact across both Windows and Linux environments, with operations aligned to financially motivated enterprise ransomware activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The following encryptor sample dubbed LukaLocker was identified encrypting victim files with the .nba file extension. A linux version of LukaLocker was also identified on the victim’s network.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
LukaLocker is a ransomware encryptor used in Volcano Demon intrusions. It targets Windows and Linux systems, encrypts files with the .nba extension, uses API obfuscation and dynamic API resolution, terminates services and processes, and uses ChaCha8 for file encryption with Curve25519/ECDH-derived key material. It supports full or partial file encryption and is used in double-extortion attacks.
LukaLocker is a ransomware family targeting both Windows and Linux systems, notable for direct extortion of executives and IT leadership via phone calls rather than using a leak site.
LukaLocker is a ransomware variant used by the Volcano Demon group. It encrypts files with a .nba extension, terminates security and backup processes, and exfiltrates data for double extortion. It is designed to evade detection through API obfuscation and dynamic API resolution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.