PureLocker is a targeted ransomware family associated with enterprise-focused intrusions, particularly against servers and databases. It is written in PureBasic and has been linked by researchers to the same malware-as-a-service ecosystem behind the More_eggs malware suite, including the Golden Chickens/Venom Spider cluster. PureLocker is implemented as a DLL and has been observed masquerading as a legitimate cryptographic library component to blend into victim environments.
The malware encrypts database and non-database files using AES, generating a unique random key and IV for each file, and appends a CR1-themed extension to encrypted data before dropping a ransom note. Its execution flow includes multiple anti-analysis and environmental checks: it expects invocation through regsvr32 with specific arguments, verifies administrative privileges, performs debugger-detection checks through process environment structures, and uses hook-evasion techniques involving ntdll mapping. It also includes logic tied to environmental conditions and manipulates shadow storage during execution, behavior consistent with efforts to hinder recovery.
PureLocker appears intended for selective, hands-on deployment rather than indiscriminate mass spam campaigns. Reporting has characterized it as suitable for targeted attacks against enterprise infrastructure, and related ecosystem reporting ties PureLocker to TerraCrypt, a ransomware plugin within the More_eggs framework. PureLocker has also been noted among ransomware operations that used Linux variants, indicating cross-platform operational interest beyond Windows in some campaigns. The malware’s low detection rate at the time it was publicly analyzed, combined with its anti-analysis features and controlled execution requirements, suggests an emphasis on stealth and operator-managed deployment.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
PureLocker is a dynamic link library (DLL) that masquerades as a Crypto++ Library component with the original filename of cryptopp.dll.
Then PureLocker adjusts the amount of space allocated to store volume shadow copies using the command: wmic shadowstorage SET MaxSpace=337000000.
Shadows copies were removed, original files were overwritten, renamed and deleted using safe methods.
It expects to be executed with the Windows regsvr32 utility using the command-line arguments /s /i. This command will execute the DllRegisterServer() export function.
By targeting virtual machines, ransomware operators can also encrypt multiple servers at once with a single command. In June, researchers spotted a new REvil ransomware Linux encryptor designed to target VMware ESXi virtual machines, a popular enterprise virtual machine platform.
By targeting virtual machines, ransomware operators can also encrypt multiple servers at once with a single command. In June, researchers spotted a new REvil ransomware Linux encryptor designed to target VMware ESXi virtual machines, a popular enterprise virtual machine platform.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as part of Atomic Red Team validation tests for ransomware detection.
Named ransomware family explicitly described as associated with the TerraCrypt component of more_eggs.
Ransomware operation mentioned as having used Linux variants in attacks.
A targeted ransomware variant written in PureBasic that masquerades as cryptopp.dll, expects execution via regsvr32 with /s /i, performs anti-debugging and hook-evasion checks, reduces shadow copy storage, encrypts files using AES, appends the .CR1 extension, and drops a ransom note demanding contact via ProtonMail. It is described as aimed at enterprise servers and databases, while also encrypting non-database files.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.