Skip to main content
Mallory
Back to malware
MalwareRansomwareUsed by 1 actorExploits 2 CVEs

MountLocker

MountLocker is ransomware referenced in reporting on intrusion activity and malware delivery chains. The provided content links MountLocker to at least two access-and-deployment ecosystems. First, CrowdStrike-assessed activity described Prophet Spider as an access broker that exploited unpatched Oracle WebLogic Server vulnerabilities, including CVE-2020-14882 and CVE-2020-14750, as well as older Oracle flaws such as CVE-2016-0545 and SQL injection, to gain initial access to victim environments and likely sell that access to ransomware operators including MountLocker. In that reporting, Prophet Spider was observed compromising vulnerable web servers and public-facing applications, and researchers reported incidents where its intrusions preceded ransomware deployment. Second, CERT-FR/ANSSI reporting states that the BumbleBee loader has previously been used to deploy ransomware including MountLocker, alongside Conti, Quantum, Diavol, and Akira. BumbleBee distribution methods in the cited report include phishing, malicious advertisements, malicious sites offering fake software, email thread hijacking, and delivery by other malware such as Emotet and Raspberry Robin. The content does not provide technical details on MountLocker’s internal functionality, encryption behavior, specific victim sectors, operating systems, or direct indicators of compromise.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

2 CVES
CVE-2020-14750Unauthenticated RCE in Oracle WebLogic Server ConsoleExploited in the wild

Researchers noticed a recent trend in which Prophet Spider uses CVE-2020-14882 and CVE-2020-14750 to get a foothold into target environments. Both CVEs relate to path traversal vulnerabilities that enable an attacker to access the WebLogic administrative console, which then allows for unauthenticated remote code execution.

via dark readingdarkreading.com
CVE-2020-14882Oracle WebLogic Server Console Authentication Bypass and RCEExploited in the wild

Researchers noticed a recent trend in which Prophet Spider uses CVE-2020-14882 and CVE-2020-14750 to get a foothold into target environments. Both CVEs relate to path traversal vulnerabilities that enable an attacker to access the WebLogic administrative console, which then allows for unauthenticated remote code execution.

via dark readingdarkreading.com
THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
ToyMaker

Prophet Spider functioned as an access broker and likely granted access to Egregor and MountLocker ransomware operators in exchange for payment.

via dark readingdarkreading.com
MITRE ATT&CK

Techniques & procedures

1 distinct technique documented for this family, organized by ATT&CK tactic.

Initial Access

1 technique
T1190Exploit Public-Facing ApplicationEvidence1

"attackers exploit Oracle WebLogic server flaws to access target environments" ... "uses CVE-2020-14882 and CVE-2020-14750 to get a foothold" ... "path traversal vulnerabilities that enable an attacker to access the WebLogic administrative console, which then allows for unauthenticated remote code execution." | "Prophet Spider has also been seen using older Oracle CVEs such as CVE-2016-0545, as well as gaining initial access via SQL injection."

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities2

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping1

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.