WastedLocker is a ransomware family used against a variety of targets worldwide and widely attributed to Evil Corp (also referenced in connection with INDRIK SPIDER and Microsoft’s DEV-0243/EvilCorp cluster). Reporting in the provided content links WastedLocker to major incidents including the Garmin attack, and notes that Evil Corp later shifted from WastedLocker to closely related variants such as Hades, in part to evade OFAC sanctions and attribution pressure.
Behaviorally, the content states that WastedLocker enumerates removable drives prior to encryption, deletes shadow volumes to inhibit recovery, and creates and establishes a service that runs until encryption is complete. It also copies a random file from the Windows System32 directory into %APPDATA% under a different hidden filename. Registry-related behavior explicitly mentioned includes modifying values under Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap and checking for specific registry keys related to the UCOMIEnumConnections and IActiveScriptParseProcedure32 interfaces.
The content also links WastedLocker to broader criminal access ecosystems. TA569/SocGholish (FakeUpdates) activity has been linked to ransomware families including WastedLocker, and Microsoft states DEV-0206 partnered with DEV-0243/EvilCorp to deploy WastedLocker in early partnerships. Additional reporting notes that SocGholish campaigns have delivered follow-on tooling such as Cobalt Strike and NetSupport in intrusion chains associated with WastedLocker. One cited report states WastedLocker encrypts data but does not exfiltrate it, allowing recovery from backups where available.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
As for example, he sold a ransomware in 2019 (WastedLocker) and his coding style is noted around other malware families like Caberp.
WastedLocker — A ransomware family that has been used against a variety of targets worldwide.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
The content repeatedly describes malware and threat actors decoding, decrypting, deobfuscating, or unpacking payloads, strings, configuration data, commands, and C2 responses prior to execution or use.
Agent Tesla has created hidden folders. AppleJeus has added a leading . to plist filenames, unlisting them from the Finder app and default Terminal directory listings. APT28 has saved files with hidden file attributes. FIN13 has created hidden files and folders within a compromised Linux system /tmp directory and also used attrib.exe to hide gathered local host information.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
ADVSTORESHELL can list connected devices. APT28 uses a module to receive a notification every time a USB mass storage device is inserted into a victim. APT37 has a Bluetooth device harvester, which uses Windows Bluetooth APIs to find information on connected Bluetooth devices.
Numerous ransomware/wiper examples enumerate files before encryption, such as "BlackCat can enumerate files for encryption", "NotPetya searches for files ending with dozens of different file extensions prior to encryption", and "WastedLocker can enumerate files and directories just prior to encryption."
Akira will delete system volume shadow copies via PowerShell commands. Avaddon deletes backups and shadow copies using native system tools. Babuk has the ability to delete shadow volumes using vssadmin.exe delete shadows /all /quiet. BlackCat can delete shadow copies using vssadmin.exe delete shadows /all /quiet and wmic.exe Shadowcopy Delete; it can also modify the boot loader using bcdedit /set {default} recoveryenabled No.
49 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware family explicitly linked in the content as associated with SocGholish activity.
Ransomware operation attributed in the article to Evil Corp.
A ransomware family deployed in post-SocGholish intrusion activity and explicitly attributed in the content to EvilCorp.
WastedLocker is a ransomware family described as a downstream payload/customer relationship tied to SocGholish access sales.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.