LockCrypt is a Windows ransomware family associated with intrusions into corporate environments, including campaigns in which attackers obtained access through brute-force attacks against exposed Remote Desktop services. It encrypts victim files, renames them with a distinctive locked-file extension scheme, deletes shadow copies to hinder recovery, and establishes persistence so the malware and ransom instructions remain active after reboot. Observed variants also modify Windows logon notice settings to display an extortion message and maintain a victim identifier used during the encryption workflow.
LockCrypt has been observed using a comparatively simple file-encryption routine based on XOR operations and byte swapping, with victim-specific data retrieved from attacker-controlled infrastructure and incorporated into the encryption process. It also deploys process-termination logic to kill non-whitelisted processes before encryption, a behavior consistent with defense evasion and improving access to open files. Persistence has been achieved by altering Windows startup-related configuration so the ransomware executes automatically and opens the ransom note for the user.
The family has also been linked to post-compromise privilege escalation through use of CVE-2016-7255 in some operations, indicating that operators or affiliates combined the ransomware with publicly traded or criminally sourced Windows local privilege escalation exploits. Reporting has further noted that the group behind LockCrypt began as customers of the Satan ransomware-as-a-service ecosystem before developing its own strain. LockCrypt is primarily associated with financially motivated attacks against Windows-based corporate servers and enterprise environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2016-7255 Classification: 1-Day Basic Description: Memory corruption in NtUserSetWindowLongPtr Used by the following malware families: LockCrypt | CVE-2016-7255 ... Used by the following malware families: LockCrypt.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
After that it creates a “Hacked” subkey in the following registry key. “SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon”
All of the exploits that we found related to this actor were 1-Day exploits for Local Privilege Escalation (LPE) vulnerabilities in Windows.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only because BabLock borrowed ransom note text from it.
Ransomware family listed as using PlayBit's exploit for CVE-2016-7255.
Named as a ransomware strain whose operators previously used Satan RaaS before creating their own malware.
LockCrypt is a ransomware variant spread via RDP brute-force compromises of corporate servers. It encrypts files, renames them with a .lock extension, installs itself for persistence, deletes shadow backups via vssadmin, modifies Winlogon registry keys to display a warning and launch itself at logon, sends victim information to a C2 server, and uses server-provided data in its file-encryption routine.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.