Macaw Locker is a Windows ransomware family associated with the Evil Corp cybercrime group and widely assessed as part of the same lineage as WastedLocker, Hades, Phoenix Locker, and PayloadBIN. It emerged in 2021 and has been linked to disruptive intrusions against large enterprises, including organizations in manufacturing and media. Multiple analyses assess with high confidence that Macaw Locker is derived from the Hades codebase, with notable overlap in core functionality and broader tradecraft consistent with Evil Corp’s post-sanctions rebranding strategy.
Macaw Locker encrypts victim files and is used in targeted enterprise extortion operations. Reported behavior includes victim-specific execution controls requiring a custom command-line token before the payload will run, suggesting deliberate operator gating and reduced risk of uncontrolled execution. The malware also incorporates anti-analysis and defense-evasion features such as API hashing, indirect API calls, and runtime import resolution. Across its lineage, related variants have shared implementation patterns for file and drive enumeration, encryption support routines, shadow copy deletion, and self-deletion logic.
Macaw Locker has been observed in operations attributed to Evil Corp after the group shifted away from more attributable tooling following U.S. sanctions. In this period, Evil Corp commonly relied on alternative initial access and post-compromise tooling, including SocGholish/FakeUpdates delivery chains and Cobalt Strike, to obscure attribution and sustain ransomware activity. Macaw Locker therefore fits into a broader cluster of financially motivated, human-operated ransomware intrusions characterized by tailored deployment, enterprise disruption, and high-value ransom demands.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This week, it was discovered that both attacks were conducted by a new ransomware known as Macaw Locker.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware operation attributed in the article to Evil Corp.
Ransomware name listed among tools associated with GOLD DRAKE/Evil Corp (no additional detail provided in the content).
Ransomware name listed among tools associated with GOLD DRAKE/Evil Corp (no additional detail provided in the content).
Ransomware variant reportedly used by Evil Corp after sanctions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.