XingLocker is a Windows ransomware family associated with financially motivated intrusion activity and observed in operations where initial access malware such as IcedID was used to rapidly progress from compromise to ransomware deployment. It has been linked in reporting to the cybercrime ecosystem around Conti and was later described as having rebranded as Quantum. Activity associated with XingLocker followed the broader big-game hunting ransomware model, in which operators used commodity or brokered access, post-exploitation tooling, and domain-wide intrusion techniques before encrypting victim environments.
Observed tradecraft in incidents involving XingLocker included use of IcedID as an entry point, followed by extensive hands-on-keyboard post-exploitation. Operators used common Windows-native and third-party tooling for discovery, credential access, persistence, and lateral movement. Reported behaviors included credential dumping from LSASS, Active Directory and host discovery, deployment of Cobalt Strike for command and control and follow-on operations, creation of persistence through scheduled tasks and additional accounts, movement across the network via remote administration mechanisms, and attempts to disable endpoint protections. In at least one XingLocker-related intrusion, attackers used scripts derived from publicly available tooling to disable antivirus and EDR defenses before ransomware execution.
XingLocker targeted Windows enterprise environments and fits the pattern of ransomware operations focused on full-domain compromise and high-value organizational impact rather than opportunistic single-host infections. Its operational context places it within the broader ransomware affiliate and initial-access ecosystem that relied on malware loaders, credential theft, lateral movement, and defense evasion to prepare victim networks for encryption and extortion.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
XingLocker is referenced as the ransomware payload in a campaign involving IcedID.
Ransomware referenced as a payload delivered via IcedID; noted as having rebranded to Quantum.
Ransomware family explicitly linked to an intrusion chain beginning with IcedID.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.