Blue Locker is a Windows ransomware family first observed in late 2021 and publicly documented from early 2022. It encrypts files on compromised endpoints and servers, deletes backup snapshots, stops services to increase encryption coverage, and leaves ransom instructions for private negotiation. Reported operations use double extortion, combining encryption with claimed data theft and threats to disclose stolen information. A publicly documented 2025 intrusion against Pakistan Petroleum Limited disrupted financial operations and affected servers and virtual machines, bringing particular attention to oil and gas and other critical-sector organizations in Pakistan. Reported access methods include phishing, malicious attachments and links, drive-by downloads, trojanized software, unsafe file-sharing services, and insecure remote access. Blue Locker has been reported to use a PowerShell-based loader, registry-based persistence and UAC-bypass techniques, security-tool impairment, process and system discovery, local-network and removable-media propagation, and obfuscation and anti-analysis measures. Relationships to the Proton/Shinra ransomware lineage and the public MemeCryptor codebase have been reported, but operator attribution remains unresolved; Chinese-language artifacts are not reliable evidence of attribution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
As a delivery channel, Blue Locker “can propagate across local networks and removable storage devices.”
“The group also exploits insecure remote access configurations...”
“The group also exploits insecure remote access configurations, drive-by downloads...”
“Reporting identify phishing emails with malicious attachments or links as the primary delivery mechanism.”
“Modifies system services for persistence and privilege escalation.”
Blue Locker searches for a unique obfuscated string ... an XOR-encoded variant of “Chrome.exe.”
“Timestomping technique is used to alter file timestamps, making it difficult to detect during forensic analysis.”
“Implements obfuscation and deobfuscation to evade detection by security tools and analysts.”
“Performs registry queries to gather system configuration and installed software information.”
Blue Locker locates the obfuscated Chrome.exe target process and “forcibly terminates it”; the report also states it “enumerates running processes.”
“Explores file and directory structures to find valuable files for encryption or exfiltration.”
25 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Double-extortion ransomware that encrypts files, deletes backups and shadow copies, stops services, and reportedly exfiltrates data before encryption. It uses RSA with a bulk symmetric cipher, appends .blue in the described artifact set, and drops restore_file.txt ransom notes.
A Windows ransomware family that encrypts files and virtualized environments, deletes shadow copies and backups, disables defenses, and allegedly exfiltrates data for double extortion. It uses private ProtonMail, Jabber, and Tox channels for negotiation rather than a public leak site.
A ransomware family used against Pakistani government and critical-infrastructure organizations. It uses a PowerShell-based loader, establishes persistence through the Registry Run key, deletes shadow copies, terminates Chrome to access locked password-database files, encrypts files using AES and RSA, and conducts double-extortion threats involving purportedly exfiltrated data.
Ransomware that spreads via phishing, drive-by downloads, insecure remote access, and lateral propagation; encrypts files (adds .blue or .bulock16 extensions) and drops ransom notes (e.g., HOW_TO_BACK_FILES.html, restore_file.txt) demanding payment and sometimes threatening data leakage.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.